<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/gdpr" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Gdpr ]]></title>
                <link>https://www.itpro.com/security/data-protection/gdpr</link>
        <description><![CDATA[ All the latest gdpr content from the ITPro team ]]></description>
                                    <lastBuildDate>Wed, 22 Jan 2025 11:54:01 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ GDPR fines might’ve dipped last year, but don’t get complacent – personal liability risks are rising ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/gdpr/gdpr-fines-mightve-dipped-last-year-but-dont-get-complacent-personal-liability-risks-are-rising</link>
                                                                            <description>
                            <![CDATA[ A decrease in big GDPR fines doesn’t mean it’s plane sailing for enterprises in 2025 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sXx3K7v5FyMfXE3orVGtPS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2PNfqhutSeDbXWYknvreHR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jan 2025 11:54:01 +0000</pubDate>                                                                                                                                <updated>Wed, 22 Jan 2025 14:42:38 +0000</updated>
                                                                                                                                            <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2PNfqhutSeDbXWYknvreHR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GDPR concept image showing &#039;GDPR&#039; lettering on a digital interface with padlock icons protruding from the center.]]></media:description>                                                            <media:text><![CDATA[GDPR concept image showing &#039;GDPR&#039; lettering on a digital interface with padlock icons protruding from the center.]]></media:text>
                                <media:title type="plain"><![CDATA[GDPR concept image showing &#039;GDPR&#039; lettering on a digital interface with padlock icons protruding from the center.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2PNfqhutSeDbXWYknvreHR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The number of <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">GDPR fines</a> issued last year fell by a third compared with 2023 , according to new research, but this doesn't mean data protection authorities are getting any softer.</p><p>DLA Piper's <a href="https://www.dlapiper.com/en-gb/insights/publications/2025/01/dla-piper-gdpr-fines-and-data-breach-survey-january-2025" target="_blank"><u><em>GDPR Fines and Data Breach Survey</em></u></a><em> </em>found that €1.2 billion in penalties was issued during the year, down 33%. This marks the first time the amount has fallen since the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> was introduced in May 2018.</p><p>Thanks to the many tech firms headquartered in the country, Ireland remains the biggest enforcer, with the Irish Data Protection Commission issuing €3.5 billion in fines since May 2018.</p><p>That's more than four-times the value of fines issued by the second-placed Luxembourg Data Protection Authority, which has issued €746.38 million over that time. Total fines reported since the start of GDPR in 2018 now stand at €5.88 billion.</p><p>But DLA Piper said last year's big drop doesn't represent a weakening of enforcement; the year-on-year trend remains upwards.  </p><p>It's actually due to a skewing of the 2023 figures by the record-breaking <a href="https://www.itpro.com/security/data-protection/meta-to-fight-unjustified-record-dollar13-billion-gdpr-fine">€1.2 billion penalty issued by the Irish DPC against Meta</a> in 2023, which remains the largest ever imposed.</p><p>"The headline figures in this year's survey have, for the first time ever, not broken any records so you may be forgiven for assuming a cooling of interest and enforcement by Europe's data regulators. This couldn't be further from the truth," said Ross McKean, partner and chair of DLA Piper's UK data protection and cyber practice. </p><p>"From growing enforcement in sectors away from big tech and social media, to the use of the GDPR as an incumbent guardrail for AI enforcement as AI specific regulation falls into place, to significant fines across the likes of Germany, Italy and the Netherlands, and the UK's shift away from fine-first enforcement – GDPR enforcement remains a dynamic and evolving arena."</p><p>It's still the big tech companies and social media giants that are getting the biggest fines, with nearly all of the top ten largest fines since 2018 imposed on firms operations in this sector. </p><p>Across 2024, the Irish Data Protection Commission issued fines of <a href="https://www.itpro.com/security/data-protection/linkedin-fined-eur310-million-for-gdpr-breaches">€310 million against LinkedIn</a> and €251 million (£208m) against Meta. In August 2024, the Dutch Data Protection Authority issued a fine of €290 million against a well-known ride-hailing app.  </p><p>The UK was an outlier in 2024, issuing very few fines. Information Commissioner John Edwards previously noted that he wasn’t in favor of issuing fines. </p><p>Edwards said these were unlikely to have significant impact and would tie the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">ICO</a> up in years of litigation.</p><h2 id="gdpr-fines-mirrored-by-personal-liability-risks">GDPR fines mirrored by personal liability risks</h2><p>Perhaps most significantly, there's been an increased focus on failures in governance and oversight, with some specifically calling out failings of management bodies. </p><p>Most notably, the Dutch Data Protection Commission announced an investigation into whether it can hold the directors of Clearview AI <a href="https://www.itpro.com/security/data-breaches/threat-of-personal-liability-has-cisos-sweating">personally liable</a> for numerous <a href="https://www.itpro.com/security/gdpr-fines-just-6-of-the-total-cost-of-data-breaches">GDPR breaches</a>, following a €30.5 million fine against the company. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="phuxQVkJh9chhLuGNCqKKA" name="Giving your people the tools to stay productive, wherever they spend their working day" caption="" alt="Giving your people the tools to stay productive, wherever they spend their working day" src="https://cdn.mos.cms.futurecdn.net/phuxQVkJh9chhLuGNCqKKA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Virgin Media O₂ Business and Samsung)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/giving-your-people-the-tools-to-stay-productive-wherever-they-spend-their-working-day"><em>Freedom to work where you want</em></a></p></div></div><p>DLA Piper said this potentially signals a shift in focus by regulators, who recognize the power of personal liability to focus minds and drive better compliance.  </p><p>"For me, I will mostly remember 2024 as the year that GDPR enforcement got personal," said McKean. </p><p>"As the Dutch DPA champions personal liability for the management of  Clearview AI, 2025 may well be the year that regulators pivot more to naming and shaming and personal liability to drive data compliance."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Four years on, how's UK GDPR holding up? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/gdpr/four-years-on-hows-uk-gdpr-holding-up</link>
                                                                            <description>
                            <![CDATA[ While some SMBs are struggling, most have stepped up to the mark in terms of data governance policies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PCUFe9zbJJEQSsBpg9nG7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jan 2025 12:05:55 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jan 2025 17:24:42 +0000</updated>
                                                                                                                                            <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:description>                                                            <media:text><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:text>
                                <media:title type="plain"><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It's been four years since the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">UK General Data Protection Regulation (GDPR) </a>came into force after the UK left the European Union (EU). </p><p>However, while the UK legislation remains aligned with that of the EU, it gives the UK the independence to keep the framework under review.</p><p>Like the EU GDPR, the UK version places requirements on organizations that process personal data, based on seven principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality and accountability. </p><p>Charlie Bromley-Griffiths, senior legal counsel at legal document management software form Conga, said that while the legislation has delivered marked benefits, lingering issues remain.</p><p>"Over the last four years, UK businesses have made substantial strides in aligning with UK GDPR requirements. Companies have implemented stronger data governance policies, enhanced security protocols and prioritized the rights of data subjects," Bromley-Griffiths said.</p><p>"However, challenges still remain, particularly for small and medium-sized enterprises struggling with the complexity and cost of full compliance. GDPR mandates stringent measures to safeguard consumer data, which includes data storage, processing and transfer practices, all of which impacts organizations’ data strategies and operational costs."</p><p>Brexit has also caused issues with regard to the transfer of personal data between the UK and the European Economic Area (EEA), along with UK controllers who have an establishment or customers in the EEA, or who monitor individuals in the area. </p><p>While the EU GDPR still applies to this processing, the way organizations interact with European data protection authorities has changed.</p><p>"The international data landscape is now rather complex. UK businesses handling data from the European Union (EU) must also comply with the EU GDPR," said Bromley-Griffiths. </p><p>"Then, of course, there is the <a href="https://www.itpro.com/business/policy-and-legislation/us-uk-data-bridge-everything-you-need-to-know">US-UK data bridge</a>, which forms part of the <a href="https://www.itpro.com/business/policy-and-legislation/eu-us-data-transfer-framework-will-be-overturned-within-five-years-says-expert">EU-US Data Privacy Framework</a> and permits the flow of EU-based data to the United States under certain conditions." </p><p>All this, she said, highlights the importance of maintaining two or more compliance strategies to make sure operations across borders go smoothly – and, ultimately, keep the trust of customers, reassuring them that their data is safe.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="69vPgVDk9D2V2RrxrY7DjV" name="The Business Value of Dell PowerFlex_listing.jpg" caption="" alt="A whitepaper from Dell and Intel on the business value of Dell Powerflex, with image of data  in a funnel shape" src="https://cdn.mos.cms.futurecdn.net/69vPgVDk9D2V2RrxrY7DjV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell | Intel)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-storage/the-business-value-of-dell-powerstore"><em>Dell PowerStore could improve your business performance</em></a></p></div></div><p>Looking ahead, Bromley-Griffiths expects regulatory bodies to look at cracking down harder on repeat offenders or businesses that have suffered significant data breaches. </p><p>Meanwhile, the UK GDPR is likely to be amended, with the introduction last October of the Data Use and Access Bill in the House of Lords. With this bill, and in future, the UK is unlikely to diverge significantly from EU legislation. </p><p>It currently enjoys 'data adequacy' with the EU, meaning that personal data can be transferred freely between the two. If this were lost, it could be an economic disaster.</p><p>However, more minor changes, said Bromley-Griffiths, could be on the cards.</p><p>"Given how quickly cyber threats are evolving, the UK GDPR standards may be updated. Businesses need to have the appropriate tools and measures in place to ensure that they are ready to adapt to any legislative changes," she said. </p><p>"Organizations must remain committed to investing in their employee’s ongoing education but also in the right technology to safeguard personal data."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Firms have paid out more than $4.8 billion in GDPR fines since 2018 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/gdpr/firms-have-paid-out-more-than-dollar48-billion-in-gdpr-fines-since-2018</link>
                                                                            <description>
                            <![CDATA[ Tech giants headquartered in Ireland attract the biggest GDPR fines ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MVMR2x9KRT5ZcN98jsPX6b</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pH8dmKXEPSaRKAUX3mgWN8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 May 2024 12:20:52 +0000</pubDate>                                                                                                                                <updated>Wed, 29 May 2024 09:49:09 +0000</updated>
                                                                                                                                            <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pH8dmKXEPSaRKAUX3mgWN8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data protection and GDPR concept image showing multiple padlocks on a green background with one opened padlock.]]></media:description>                                                            <media:text><![CDATA[Data protection and GDPR concept image showing multiple padlocks on a green background with one opened padlock.]]></media:text>
                                <media:title type="plain"><![CDATA[Data protection and GDPR concept image showing multiple padlocks on a green background with one opened padlock.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pH8dmKXEPSaRKAUX3mgWN8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Businesses have forked out €4.5 billion for <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> violations over the last six years, with Spain, Italy, and Germany imposing the <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">biggest fines</a>.</p><p>Research from security firm Nordlayer shows that individual data protection authorities (DPAs) have between them issued 2,072 violation decisions since 2018 under the legislation.</p><p>"We&apos;ve witnessed businesses across industries change their data handling practices and invest in security measures to achieve compliance," said Carlos Salas, <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> expert at NordLayer.</p><p>"While full compliance has been challenging for many companies, the GDPR&apos;s impact in empowering individuals and holding organizations accountable for data mishandling cannot be overstated. It has reshaped the digital landscape, forcing a much-needed prioritization of privacy rights."</p><p>Spanish businesses were the worst offenders, violating GDPR 842 times and paying out €80 million in fines since 2018. </p><p>Italy was second on the list; while the country&apos;s organizations have received half the number of GDPR violations compared with Spain, they&apos;ve paid nearly three times as much in fines. Companies in Italy, meanwhile, were issued 358 fines and paid nearly €229 million.</p><p>German organizations fell victim to 186 fines, resulting in €55 million worth of penalties. Romanian businesses weren&apos;t far behind with 179 fines - but have paid only €1.1 million in fines. Poland rounds out the top five, with companies receiving 73 fines, resulting in nearly €4 million losses.</p><h2 id="ireland-isn-x2019-t-scared-to-dish-out-gdpr-fines">Ireland isn’t scared to dish out GDPR fines</h2><p>In terms of the biggest payouts, it&apos;s Ireland that stands out, with €2.8 billion in fines issued since 2018. The main reason, of course, is that many of the largest tech companies, such as Meta and TikTok, have registered their European subsidiaries there and have been hit with multi-million-dollar fines.</p><p>Indeed, it&apos;s <a href="https://www.itpro.com/policy-legislation/data-protection/366996/meta-fine-gdpr-breaches">Meta that&apos;s far and away the biggest violator of GDPR</a>, having been slapped with six of the EU&apos;s ten biggest fines.</p><p>The biggest cost the company €1.2 billion, for insufficient legal basis for data processing in 2023. There were also two fines of around €400 million for non-compliance with general data processing principles.</p><p>In 2021, Amazon had to pay €746 million to Luxembourg’s data protection authorities; while last year, TikTok paid €345 million. Google was punished twice in 2021 for having insufficient legal basis for data processing, and paid €90 million and €60 million for separate violations.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LbTZ6xzM9S46sHCntnXWLf" name="Data governance for data-driven organizations.jpg" caption="" alt="Data governance for data-driven organizations whitepaper" src="https://cdn.mos.cms.futurecdn.net/LbTZ6xzM9S46sHCntnXWLf.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ibm-data-governance-for-data-driven-organizations"><em>Master your data management</em></a></p></div></div><p>And it&apos;s insufficient legal basis for data processing that&apos;s the most common reason for a fine, with 635 cases since 2018, costing companies €1.6 billion. For non-compliance with general data processing principles, organizations were fined 578 times and paid over €2 billion.</p><p>"Achieving and maintaining GDPR compliance is an ongoing journey, not a one-time destination," Salas said.</p><p>"<a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30326/what-is-a-data-protection-officer">Data protection</a> regulations evolve, and cyber threats become more sophisticated, so businesses must remain proactive in their data privacy and security approach."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Italy’s ChatGPT ban branded an “overreaction” by experts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/370377/italys-chatgpt-ban-branded-an-overreaction-by-experts</link>
                                                                            <description>
                            <![CDATA[ Regulators across Europe will continue to assess the privacy and age concerns of AI models, but Italy's ban may not last ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mqoXy5CM8ufKs7PNpUVsKs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4xKAcXujfaETmnbdkM9Kaf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Apr 2023 11:18:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4xKAcXujfaETmnbdkM9Kaf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Somebody holding a smartphone with ChatGPT written on its face]]></media:description>                                                            <media:text><![CDATA[Somebody holding a smartphone with ChatGPT written on its face]]></media:text>
                                <media:title type="plain"><![CDATA[Somebody holding a smartphone with ChatGPT written on its face]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4xKAcXujfaETmnbdkM9Kaf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The decision by Italian regulators to ban access to ChatGPT has drawn criticism from industry experts, branding it a hindrance to innovation and a distraction from legitimate concerns around AI and privacy.</p><p>Italian authorities banned access to <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a> at the end of March. The degree to which the technology collects data for algorithmic training purposes was deemed to have no legal basis.</p><p>The lack of age verification embedded in the technology, which could shield underage users from inappropriate content, was also highlighted as a key issue.</p><p>The Italian data protection authority, Garante per la protezione dei dati personali, issued a decision on 31 March declaring that it would temporarily suspend the processing of Italian user data by OpenAI.</p><p>OpenAI has restricted access to ChatGPT in Italy while it works with Garante to establish an understanding.</p><p>Those who purchased <a href="https://www.itpro.com/business/business-strategy/369989/openai-launches-chatgpt-plus-greater-revenue" data-original-url="https://www.itpro.com/business/business-strategy/369989/openai-launches-chatgpt-plus-greater-revenue">ChatGPT Plus</a> subscriptions in March will receive a refund, and all subscribers in the region have had their recurring payments paused.</p><p>The ban prompted debate among AI and legal experts who have questioned the legitimacy and wiseness of the decision.</p><p>Andy Patel, researcher at WithSecure, called the ruling an “overreaction” and warned that it could put Italy at a disadvantage when it comes to AI development.</p><p>“ChatGPT is a useful tool that enables creativity and productivity - by shutting it off, Italy has cut off perhaps the most important tool available to our generation," he said. </p><p>"All companies have security concerns, and, of course, employees should be instructed to not provide ChatGPT and similar systems with company-sensitive data. Such policies should be controlled by individual organisations and not by the host country.”</p><p>Others have suggested that the ban will not last, and is a distraction from the wider issues of privacy and security that must be addressed when it comes to large language models (LLMs).</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="o2sFTU3ik7eqwcDQVnn9eB" name="o2sFTU3ik7eqwcDQVnn9eB.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/o2sFTU3ik7eqwcDQVnn9eB.png" mos="https://cdn.mos.cms.futurecdn.net/o2sFTU3ik7eqwcDQVnn9eB.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Selecting a fit-for-purpose server platform for datacentre infrastructure</strong></p><p class="fancy-box__body-text">Driving the change in infrastructure</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/367141/selecting-a-fit-for-purpose-server-platform-for-datacentre-infrastructure" data-original-url="/infrastructure/367141/selecting-a-fit-for-purpose-server-platform-for-datacentre-infrastructure">FREE DOWNLOAD</a></p></div></div><p>“‘Banning’ these models - whatever that term means in this context - is simply encouraging more perfidy on the part of these companies to restrict access and concentrates more power in the hands of tech giants who are able to sink the money into training such models,” said Erick Galinkin, principal artificial intelligence researcher at Rapid7.</p><p>“Rather, we should be looking for more openness around what data is collected, how it is collected, and how the models are trained.”</p><p>Concerns around the centralisation of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> in the hands of big tech at present have led to calls for a 'democratisation' of the technology.</p><p>AI model leakers have called for the stolen Meta LLM LLaMA to be <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370331/calls-for-ai-models-stored-on-bitcoin-gain-traction" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/370331/calls-for-ai-models-stored-on-bitcoin-gain-traction">stored on Bitcoin to maintain free distribution</a>, while <a href="https://www.itpro.com/cloud/370113/aws-and-hugging-face-partner-to-democratise-ml-ai-models" data-original-url="https://www.itpro.com/cloud/370113/aws-and-hugging-face-partner-to-democratise-ml-ai-models">AWS and Hugging Face partnered to improve access to models</a>.</p><p>ChatGPT raised eyebrows last month when a <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370315/chatgpt-privacy-flaw-exposes-users-chatbot-interactions" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/370315/chatgpt-privacy-flaw-exposes-users-chatbot-interactions">privacy flaw exposed users' chatbot interactions</a>, the first real blow to the company's image since its early <a href="https://www.itpro.com/technology/artificial-intelligence-ai/361603/openai-tool-previously-thought-too-dangerous-for-the" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/361603/openai-tool-previously-thought-too-dangerous-for-the">GPT-3 tests were branded 'too dangerous' for public use</a>.</p><p>Michael Covington, VP of strategy at software firm Jamf, noted that there is value in a pause to ensure that AI technology proceeds in a controlled manner.</p><p>“That said, I get concerned when I see attempts to regulate common sense and force one 'truth' over another,” he added.</p><p>“At Jamf, we believe in educating users about data privacy, and empowering them with more control and decision-making authority over what data they are willing to share with third parties. Restricting the technology out of fear for users giving too much to any AI service could stunt the growth of tools like ChatGPT, which has incredible potential to transform the ways we work.”</p><p>The Italian authority also asked for OpenAI to provide notice of measures implemented to comply with its order, or face a fine as large as €20 million ($21 million) or 4% of the company’s worldwide annual turnover.</p><h2 id="could-other-countries-ban-chatgpt">Could other countries ban ChatGPT?</h2><p>In becoming the first European country to bar access to ChatGPT, Italy has set a precedent that other countries could follow.</p><p>While the ban is in place it has joined the likes of Russia, Iran, and North Korea which all ban ChatGPT as part of wider internet censorship.</p><p>OpenAI has its services geoblocked in China, meaning that businesses and consumers are unable to access ChatGPT and DALL·E in the region.</p><p>Domestic companies such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370270/baidu-unveils-ernie-ai-but-can-it-compete-with-western" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/370270/baidu-unveils-ernie-ai-but-can-it-compete-with-western">Baidu have unveiled alternative chatbots</a>, but as yet none have demonstrated abilities on par with OpenAI’s <a href="https://www.itpro.com/technology/artificial-intelligence-ai/368288/what-is-gpt-4" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/368288/what-is-gpt-4">GPT-4</a>.</p><p><em>Reuters</em> <a href="https://www.reuters.com/technology/germany-principle-could-block-chat-gpt-if-needed-data-protection-chief-2023-04-03">reported</a> that the Irish Data Protection Commission (DPC) and French Commission nationale de l'informatique et des libertés (CNIL) are in discussions with their Italian counterparts to establish the basis for the decision.</p><p>If the discussion proves convincing, regulatory bodies across the EU could soon require further privacy commitments from OpenAI.</p><p>“The Garante’s decision is a timely reminder that the excitement around generative AI must be tempered with caution,” Will Richmond-Coggan, a partner at national law firm Freeths specialising in privacy and technology, told <em>IT Pro</em>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DvESDG4wvBx7PEUaW8Dzr" name="DvESDG4wvBx7PEUaW8Dzr.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/DvESDG4wvBx7PEUaW8Dzr.jpg" mos="https://cdn.mos.cms.futurecdn.net/DvESDG4wvBx7PEUaW8Dzr.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The newest approach: Stopping bots without CAPTCHAs</strong></p><p class="fancy-box__body-text">Reducing friction for improved online customer experiences</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/bots/369340/the-newest-approach-stopping-bots-without-captchas" data-original-url="/network-internet/bots/369340/the-newest-approach-stopping-bots-without-captchas">FREE DOWNLOAD</a></p></div></div><p>“OpenAI now have an opportunity to show how it has been gathering and using personal data to train its tool in a way that is compatible with GDPR. If it can’t, it seems likely that other European supervisory authorities may follow Italy’s lead.”</p><p>Richmond-Coggan noted that the focus on the impact of ChatGPT on children and questions around age-appropriate content will keep this regulatory interest alive, and that this is a issue with which AI developers will have to contend for some time.</p><p>“With the prospect of future legislation in the UK and Europe directed both to online harms and more focused on regulating AI technologies, this is likely to be only the first of a large number of regulatory hurdles,” he added.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/370345/tech-pioneers-call-for-six-month-pause-ai-development-out-of-control" data-original-url="/technology/artificial-intelligence-ai/370345/tech-pioneers-call-for-six-month-pause-ai-development-out-of-control">Tech pioneers call for six-month pause of "out-of-control" AI development</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/370366/social-engineering-attacks-generative-ai-soar-135" data-original-url="/technology/artificial-intelligence-ai/370366/social-engineering-attacks-generative-ai-soar-135">Novel social engineering attacks soar 135% amid uptake of generative AI</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/370322/can-generative-ai-change-security" data-original-url="/technology/artificial-intelligence-ai/370322/can-generative-ai-change-security">Can generative AI change security?</a></p></div></div><p>The government’s recently released AI <a href="https://www.gov.uk/government/news/uk-unveils-world-leading-approach-to-innovation-in-first-artificial-intelligence-white-paper-to-turbocharge-growth">whitepaper</a> identifies fairness as an attribute necessary for AI innovation, and specifies that this pertains to the compliance of AI systems with laws such as <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">UK GDPR</a>.</p><p>The government has also sought to outline the transparency and redress requirements by which firms operating in the space will have to abide.</p><p>Currently, AI models operate largely on a ‘black box’ principle, in which users or even business partners have little to no oversight of the data used to train models, or what data is processed to improve models.</p><p>But the government’s approach has also been explicitly pro-innovation, and was praised by industry leaders synch as Microsoft UK CEO Clare Barclay as a “commitment to being at the forefront of progress”.</p><p>In the near future, AI companies could instead be compelled to shed more light on their data scraping, processing, and training activities.</p><p>A recent panel of experts noted that <a href="https://www.itpro.com/business/policy-legislation/370156/greater-transparency-ai-industry-avoid-regulatory-penalities" data-original-url="https://www.itpro.com/business/policy-legislation/370156/greater-transparency-ai-industry-avoid-regulatory-penalities">greater AI transparency is necessary to avoid future regulatory penalities</a>, and this debate is will only intensify in the coming years.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK’s new data protection bill “more cosmetic than substantive”, experts warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/370216/uks-new-data-protection-bill-more-cosmetic-than-substantive</link>
                                                                            <description>
                            <![CDATA[ Hailed as a major step toward “cutting red tape”, the new data bill could create more confusion for consumers and businesses alike ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qH1PkHg65fpwwNuJQDzxsU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vikkW5pGer9GtpaDZUzmhm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Mar 2023 13:08:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vikkW5pGer9GtpaDZUzmhm-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Road leading up to Westminster completely empty of people]]></media:description>                                                            <media:text><![CDATA[Road leading up to Westminster completely empty of people]]></media:text>
                                <media:title type="plain"><![CDATA[Road leading up to Westminster completely empty of people]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vikkW5pGer9GtpaDZUzmhm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New data protection laws marking the UK’s divergence from GDPR have been described as more “cosmetic than substantive” and will provide little tangible benefit for many British businesses, legal experts have warned. </p><p>The long-awaited Data Protection and Digital Information Bill, which was introduced – and later paused – in 2022 seeks to move away from the ‘one-size-fits-all' approach of European data regulation, the government said in a statement today. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill" data-original-url="/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill">Why does the UK government want to replace GDPR with the Data Reform Bill?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/370080/uk-government-cloud-acceleration-on-horizon-net-zero-slips" data-original-url="/cloud/370080/uk-government-cloud-acceleration-on-horizon-net-zero-slips">UK government cloud acceleration 'on horizon' as net zero performance slips</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties" data-original-url="/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties">ICO: The public sector isn’t getting 'an easier ride' with GDPR penalties</a></p></div></div><p>According to the government, this new ‘common-sense-led' <a href="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill" data-original-url="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill">approach to data regulation</a> will reduce costs and regulatory burdens placed on organisations in the UK and unlock £4.7 billion in savings for the economy over the next decade. </p><p>The improved bill will introduce what the government describes as a “simple, clear, and business-friendly” framework that will take the best elements of <a href="https://www.itpro.com/cloud-computing/31722/gdpr-and-the-cloud" data-original-url="https://www.itpro.com/cloud-computing/31722/gdpr-and-the-cloud">GDPR</a> and modify them to provide UK firms with greater flexibility about how they comply with data regulations. </p><p>In addition, the new data regime will provide organisations with greater confidence about when they can process personal data and “further reduce” the volume of paperwork required to demonstrate compliance for businesses. </p><p>While the announcement has been welcomed by some industry stakeholders, Will Richmond-Coggan, director and data protection law expert at Freeths, told <em>IT Pro</em> that the new regulations are “more cosmetic than substantive” and warned that some businesses may not fully reap the proposed benefits. </p><p>“Only those businesses without any international dimension are likely to be well-placed to benefit from any mooted relaxation of the regime,” he said. “Certainly, the cost savings being suggested seem to have very little foundation in reality.” </p><p>For businesses with international operations, specifically in the European Union, Richmond-Coggan noted that the new regime could force firms to operate separate compliance programmes that will likely burden them with higher long-term costs. </p><p>“Any businesses who operate both in the UK and in the EU will either adopt a uniform approach, which will ultimately be driven by the more stringent rules - wherever they originate - or try to operate separate compliance programmes in different jurisdictions, which will only add to costs,” he said. </p><p>“Furthermore, if any divergence results in a disruption to <a href="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu" data-original-url="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu">EU-UK data flows</a> – which fortunately looks to be unlikely – this will only serve to increase the compliance burden and associated costs,” he added. </p><h2 id="overhauling-prescriptive-regulations">Overhauling “prescriptive” regulations </h2><p>A key factor in the government’s <a href="https://www.itpro.com/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system" data-original-url="https://www.itpro.com/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system">overhaul of GDPR</a> is that the European-led framework “takes a highly prescriptive, top-down approach” to data protection regulation.</p><p>This, the government said, has severely limited UK organisations' flexibility to manage <a href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" data-original-url="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">privacy</a> risks and has placed “disproportionate burdens” on businesses since its introduction in 2018. </p><p>“Ministers have improved the bill to further cut down on the amount of paperwork organisations need to complete to show compliance,” the government said in a statement today. </p><p>“Now, only organisations whose processing activities are likely to pose high risks to individual’s rights and freedoms will need to keep processing records. This could include, for example, where organisations are processing large volumes of sensitive data about people’s health.” </p><p>“The new rules will give organisations more clarity about when they can process personal data without needing consent or weighing up their own interests in processing the data against an individual’s rights for certain public interest activities.” </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CnSSTVJThAf7KXUjoSqpcf" name="CnSSTVJThAf7KXUjoSqpcf.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/CnSSTVJThAf7KXUjoSqpcf.png" mos="https://cdn.mos.cms.futurecdn.net/CnSSTVJThAf7KXUjoSqpcf.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Nine steps to proactively manage data privacy and protection</strong></p><p class="fancy-box__body-text">Build trust with your employees, customers, and third parties</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/370011/nine-steps-to-proactive-manage-data-privacy-and" data-original-url="/policy-legislation/data-protection/370011/nine-steps-to-proactive-manage-data-privacy-and">FREE DOWNLOAD</a></p></div></div><p>Mona Schroedel, technology and privacy expert at Freeths, warned that while the new regulations claim to cut down on cumbersome "red tape" for businesses, the bill appears to be introducing a “reduction in accountability” and could impact consumers. </p><p>“This has a two-fold effect,” she explained. “Companies are encouraged to self-regulate and will no doubt be more prone to consider the processing taking place to be below a threshold requiring consent.” </p><p>“What is said to be providing organisations with greater confidence in processing is aimed to cut down on <a href="https://www.itpro.com/security/361576/what-are-cookies" data-original-url="https://www.itpro.com/security/361576/what-are-cookies">cookie</a> popups,” she added.</p><p>“While there will undoubtedly be consumers who will not care one way or another, recent data protection legislation has shown there is a large interest from consumers in how their data is being collected online and later used for profit by big organisations.” </p><p>Ultimately, what could be perceived as “cutting through red tape” may well lead to organisations finding themselves subject to a far higher volume of <a href="https://www.itpro.com/policy-legislation/data-protection/369977/how-to-answer-a-tricky-subject-access-request-sar" data-original-url="https://www.itpro.com/policy-legislation/data-protection/369977/how-to-answer-a-tricky-subject-access-request-sar">data subject access requests</a> to allow subjects to understand what data is being held about them. </p><p>“We can foresee that the self-regulation element will cause some consternation with consumers and be tested through the regulator and the courts,” she added. “Thereby creating additional costs and uncertainty as those challenges work their way through.” </p><h2 id="industry-support">Industry support </h2><p>Despite these concerns, the bill’s announcement has been welcomed by tech industry stakeholders and hailed a positive step to reduce burdens on organisations processing personal data. </p><p>Julian David, chief executive of techUK, said the package of reforms “builds on ambitions to bring organisations clarity and flexibility when using personal data”. </p><p>“The changes announced today will give companies greater legal confidence to conduct research, deliver basic business services, and develop new technologies such as <a href="https://www.itpro.com/strategy/28181/what-is-ai" data-original-url="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, while retaining levels of data protection in line with the highest global standards, including data adequacy with the EU,” he said. </p><p>Chris Combemale, CEO at the Data & Marketing Association (DMA), which collaborated with the government through the bill’s development, said the reforms will support the best interests of both businesses and consumers. </p><p>“We are confident that the bill should act as a catalyst for innovation and growth while maintaining robust privacy protections across the UK – an essential balance which will build consumer trust in the digital economy,” he added. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Greater transparency needed in AI industry to avoid future regulatory penalities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/370156/greater-transparency-ai-industry-avoid-regulatory-penalities</link>
                                                                            <description>
                            <![CDATA[ Understanding of AI from executive to user levels could save firms from costly disputes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7MSkanxWQtCEryRdaAuRZs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k7HecDwpcWHfYVXZtAvdSi-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Mar 2023 12:55:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/k7HecDwpcWHfYVXZtAvdSi-1280-80.png">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman looks at a man in a board room, with a bust of an android on the table while beams of light stream towards the camera]]></media:description>                                                            <media:text><![CDATA[A woman looks at a man in a board room, with a bust of an android on the table while beams of light stream towards the camera]]></media:text>
                                <media:title type="plain"><![CDATA[A woman looks at a man in a board room, with a bust of an android on the table while beams of light stream towards the camera]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k7HecDwpcWHfYVXZtAvdSi-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Firms using AI models need to commit to transparency as a matter of priority, informing staff and users on how models work, or risk facing issues in the future, according to industry experts.</p><p>Failing to share the necessary insight into the inner workings of models now could lead to regulatory penalties in the future.</p><p>The advice comes as the EU and UK have moved forward with draft bills that would regulate AI use, and compel companies to maintain a degree of transparency so that users can utilise AI models responsibly. </p><p>Firms that continue to conceal how their models work could invite fines and scrutiny, as well as reputational harm in a landscape that will increasingly demand oversight on certain high-risk AI models.</p><p>Experts speaking at PrivSec London on Tuesday also urged companies to foster an understanding of AI at the board level, to enable top-down governance and accountability of AI use.</p><p>Insight into how data is sourced and processed for AI models can also help C-suite executives to better negotiate third-party contracts, which could include clauses that allow partners to use a firm’s data to enhance their models.</p><p>This is essential for supply chain accountability, as firms could be implicated in privacy or data protection disputes based on a model built using its data.</p><p>They stressed the importance of giving employees other than data scientists, as well as users, access to information that allows them to <a href="https://www.itpro.com/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr" data-original-url="https://www.itpro.com/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr">perform a data protection impact assessment (DPIA)</a>.</p><p>“In <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> we have controller and processor, whereas in the EU AI Act you’ve got loads of different actors like developer, distributor, user, etc,” said Pratiksha Karnawat, DPO and information security officer at First Abu Dhabi Bank.</p><p>“And the onus, the responsibility of conducting the DPIA has been put on the user of that AI system. And how are they expected to do that DPIA, because if you don't even know what the system does or what it's capable of doing, how do you do a DPIA?”</p><h2 id="what-is-the-state-of-ai-legislation">What is the state of AI legislation?</h2><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=49267622&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>The <a href="https://www.itpro.com/technology/artificial-intelligence-ai/359289/ec-unveils-new-draft-ai-regulations" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/359289/ec-unveils-new-draft-ai-regulations">EU’s AI Act was proposed in April 2021</a>, laying out strict regulations against the misuse of AI models. It could be implemented as soon as the end of 2023 or the start of 2024.</p><p>Companies that do not comply with the obligations it sets out risk fines of up to 4% of total worldwide annual turnover, and up to 2% if they supply “incorrect, incomplete or misleading information”.</p><p>High-risk AI models include those that carry fundamental rights implications such as those posed by <a href="https://www.itpro.com/security/privacy/369423/uk-police-fails-ethical-tests-with-unlawful-facial-recognition" data-original-url="https://www.itpro.com/security/privacy/369423/uk-police-fails-ethical-tests-with-unlawful-facial-recognition">live facial recognition</a>, or those that influence hiring decisions and could be subject to allegations of bias such as those made against <a href="https://www.itpro.com/business/policy-legislation/370133/workday-hit-with-claims-its-ai-hiring-systems-are-discriminatory" data-original-url="https://www.itpro.com/business/policy-legislation/370133/workday-hit-with-claims-its-ai-hiring-systems-are-discriminatory">Workday’s hiring systems</a>.</p><p>“I think one of the major things we’ve done is to hold our data scientists accountable, make sure they explain how the model works to the management and to their peers, and set out those monitoring governance rules to make sure we don’t <a href="https://www.itpro.com/technology/artificial-intelligence-ai/361824/how-biased-is-your-app" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/361824/how-biased-is-your-app">bias</a> inside the model,” said Kobi Nissan, CPO and co-founder at data management firm Mine.</p><p>Mine has used static data sets for its training data even though dynamic models could produce better results more easily because “it’s the right thing to do”.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/370133/workday-hit-with-claims-its-ai-hiring-systems-are-discriminatory" data-original-url="/business/policy-legislation/370133/workday-hit-with-claims-its-ai-hiring-systems-are-discriminatory">Workday hit with claims its AI hiring systems are discriminatory</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/369570/can-the-ai-bill-of-rights-shape-global-ai-regulation" data-original-url="/business/policy-legislation/369570/can-the-ai-bill-of-rights-shape-global-ai-regulation">Can the AI Bill of Rights shape global AI regulation?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/370065/why-risk-analysts-think-ai-now-poses-a-serious-threat" data-original-url="/technology/artificial-intelligence-ai/370065/why-risk-analysts-think-ai-now-poses-a-serious-threat">Why risk analysts think AI now poses a serious threat to us all</a></p></div></div><p><a href="https://www.gov.uk/government/publications/establishing-a-pro-innovation-approach-to-regulating-ai/establishing-a-pro-innovation-approach-to-regulating-ai-policy-statement">Draft AI legislation</a> in the UK laid out six main principles including transparency around AI, with developers required to proactively or retrospectively detail the nature of an AI, the data it uses, how it processes this data, and a clear chain of accountability.</p><p>Its stated goal is to allow granularity that does not overly impede the development of AI with consideration to its considerable potential.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2NxyvDbX59c8o3q8dwk5sY" name="2NxyvDbX59c8o3q8dwk5sY.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/2NxyvDbX59c8o3q8dwk5sY.png" mos="https://cdn.mos.cms.futurecdn.net/2NxyvDbX59c8o3q8dwk5sY.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Forrester Report: Automate or die</strong></p><p class="fancy-box__body-text">Process automation has become a strategic imperative</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/369567/forrester-report-automate-or-die" data-original-url="/business-strategy/automation/369567/forrester-report-automate-or-die">FREE DOWNLOAD</a></p></div></div><p>The UK’s approach was identified as “more innovative” at the talk due to its decentralised nature, but as with GDPR, European regulation could set the tone for the sector.</p><p>This is especially true for fields such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a>, which is being developed and rolled out by large multinational firms at present and will have to comply with EU law in order to tap into the region’s lucrative market.</p><p>“I don’t think companies should be afraid of AI,” said Debbie Reynolds, CEO and chief data privacy officer at Debbie Reynolds Consulting LLC.</p><p>“I'm not saying don't use it, definitely use it, but kick the tyres look and see what's inside, have collaborative conversations about what you're trying to achieve with the AI. Make sure that you can explain every step in what’s happening.”</p><p>Reynolds responded to claims that Microsoft has not been able to explain recent aggressive outputs of its <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369791/microsoft-pins-hopes-on-chatgpt-to-supercharge-bing" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369791/microsoft-pins-hopes-on-chatgpt-to-supercharge-bing">Bing chatbot</a>, such as those documented in a <em>New York Times </em><a href="https://www.nytimes.com/2023/02/16/technology/bing-chatbot-microsoft-chatgpt.html">report</a>.</p><p>“That’s not acceptable. You have to know what is happening, why it is happening, and if it’s doing weird things you have to go back to the drawing board because you don’t want to harm users and you want to get a good result.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TikTok's two new European data centres to address data protection concerns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/370099/tiktoks-two-new-european-data-centres-wont-solve-problems</link>
                                                                            <description>
                            <![CDATA[ The company is under pressure to prove its user data isn’t being accessed by the Chinese state ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9QpBjCVCdjnPDbGJcdif79</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hV2kMBGWfiYtex4X5MG7Fj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Feb 2023 12:11:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hV2kMBGWfiYtex4X5MG7Fj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A man walking in front of a neon TikTok sign on an office wall]]></media:description>                                                            <media:text><![CDATA[A man walking in front of a neon TikTok sign on an office wall]]></media:text>
                                <media:title type="plain"><![CDATA[A man walking in front of a neon TikTok sign on an office wall]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hV2kMBGWfiYtex4X5MG7Fj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>TikTok is set to establish two new data centres in Europe as the Chinese social media platform looks to comply with local data laws.</p><p>The company, which has more than 150 million users across Europe, said that it’s finalising a plan for a second data centre in Ireland with a third-party service provider.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok" data-original-url="/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok">FCC commissioner urges Apple and Google to remove TikTok from app stores</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368974/tiktok-reportedly-suffers-data-breach" data-original-url="/security/data-breaches/368974/tiktok-reportedly-suffers-data-breach">TikTok reportedly suffers data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/information-commissioner/369164/tiktok-could-be-hit-with-ps27m-fine-for-failing" data-original-url="/policy-legislation/information-commissioner/369164/tiktok-could-be-hit-with-ps27m-fine-for-failing">TikTok could be hit with £27m fine for failing to protect children's privacy</a></p></div></div><p>It's also in talks to secure a third data centre in Europe. It didn’t specify where, though it said it will complement its Ireland operations.</p><p>European TikTok user data is set to begin migrating this year and continue into 2024.</p><p>“We also remain focused on building trust with our community by demonstrating to them that their data is secure,” said Rich Waterworth, general manager of operations, Europe, at TikTok.</p><p>“We're continuing to deliver against the data governance strategy we set out for Europe last year, which includes further reducing employee access to European user data, minimising data flows outside of Europe, and storing European user data locally.”</p><h2 id="tiktok-tightens-data-protection">TikTok tightens data protection</h2><p>TikTok announced in April 2020 that it would establish a <a href="https://www.itpro.com/strategy/29134/what-is-a-datacentre" target="_blank" data-original-url="https://www.itpro.com/strategy/29134/what-is-a-datacentre">data centre</a> in Ireland, its first in Europe, with the intent to store European user data at the facility.</p><p>The following year, the company also revealed its data governance strategy, underlining that it was committed to Europe’s <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection</a> regulations.</p><p>In April 2022, TikTok gave an update on this data governance strategy for Europe and revealed that it had finally signed a contract for a data centre in Dublin to store UK and EEA user data through a third-party service.</p><p>Operations at this site were expected to commence in early 2023. A spokesperson from TikTok told <em>IT Pro</em> that it plans to start the migration of Europe user data beginning in Q2.</p><p>TikTok has stored global user data overseas, in locations like Singapore or the US. However, it said it wanted to provide a localised solution which would help it to comply with European data sovereignty laws.</p><p>“Chinese-owned TikTok is under pressure to assure its international customers that the user data it holds is secure and safe from being accessed by the Chinese state,” said John Abbott, infrastructure analyst at 451 Research, part of S&P Global Market Intelligence.</p><p>“It’s part of a broader <a href="https://www.itpro.com/policy-legislation/data-governance/369834/building-a-data-governance-strategy" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-governance/369834/building-a-data-governance-strategy">data governance</a> plan set out by TikTok intended to reduce the flow of European user data outside of Europe.”</p><p>Abbott said that Ireland has been chosen as a location for data centres as it’s popular with hyperscalers, like AWS, Google, and Microsoft, as well as colocation providers like Digital Reality and Equinix.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cUJsxGTZgXXXWAzhLzmAED" name="cUJsxGTZgXXXWAzhLzmAED.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/cUJsxGTZgXXXWAzhLzmAED.png" mos="https://cdn.mos.cms.futurecdn.net/cUJsxGTZgXXXWAzhLzmAED.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Why technology, cyber and privacy risk management are critical for digital transformation</strong></p><p class="fancy-box__body-text">How ServiceNow Integrated Risk Management helps you embrace the digital future</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/370022/why-technology-cyber-and-privacy-risk-management" data-original-url="/business-strategy/digital-transformation/370022/why-technology-cyber-and-privacy-risk-management">FREE DOWNLOAD</a></p></div></div><p>“Opening data centres nearer customers has two benefits: It can help reduce lag by allowing access to data locally rather than thousands of miles away in China,” said Frank Jennings, partner and head of commercial at Teacher Stern LLP.</p><p>“It can also help assuage concerns over the transfer of <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">personal data</a> to China, a regime that doesn’t have a strong human rights record, let alone data protection laws comparable to <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>.”</p><p>Jennings said that keeping data in the EU won’t fix all the problems facing the company on this issue.</p><p>“It wasn’t that long ago that a New York District Court forced Microsoft to hand over customer data it was holding in its Dublin data centre under the aptly named “Clarifying Lawful Overseas Use of Data” – aka the <a href="https://www.itpro.com/security/privacy/361221/could-the-us-cloud-act-force-uk-channel-companies-to-break-gdpr" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361221/could-the-us-cloud-act-force-uk-channel-companies-to-break-gdpr">Cloud Act</a>,” he said. “No doubt the Chinese government will have such powers too.”</p><p>The new data centres are a good start, said Jennings, but won’t be enough to address the underlying issue.</p><p>In June 2022, the head of the FCC in the US <a href="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368387/fcc-commissioner-urges-apple-and-google-to-remove-tiktok">urged Apple and Google</a> to remove TikTok from their app stores due to the way it handled data.</p><p>FCC commissioner Brendan Carr said the app collects vast troves of sensitive data on its users. He pointed to a report which stated that ByteDance officials, the company which owns TikTok, had accessed the app’s sensitive data which had been collected from US citizens.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to answer a tricky subject access request (SAR) ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/369977/how-to-answer-a-tricky-subject-access-request-sar</link>
                                                                            <description>
                            <![CDATA[ How do you prove a customer is who they say they are, and how much information should you provide? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dZRTLZSuvZXr4TRHi1AK2Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jsQoshWtfv7teYLS92r6jj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 04 Feb 2023 08:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Olivia Whitcroft ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jsQoshWtfv7teYLS92r6jj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several anonymous faces imposed with binary to represent privacy]]></media:description>                                                            <media:text><![CDATA[Several anonymous faces imposed with binary to represent privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Several anonymous faces imposed with binary to represent privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jsQoshWtfv7teYLS92r6jj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There are many challenges in handling subject access requests (SARs). Some may have a clear resolution, such as not retaining emails for 20 years, while others may be relatively untested issues, where the legislation and guidance aren’t wholly clear. </p><p><a href="https://www.itpro.com/data-protection/31623/what-is-a-subject-access-request" target="_blank" data-original-url="https://www.itpro.com/data-protection/31623/what-is-a-subject-access-request">SARs</a> are among the most common queries many data controllers, and <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30326/what-is-a-data-protection-officer" target="_blank" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/30326/what-is-a-data-protection-officer">data protection officers (DPOs)</a> within organisations, will face on a daily basis. Even before GDPR, the <a href="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998" target="_blank" data-original-url="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998">Data Protection Act 1998</a> outlined the right for individuals to access their personal data held by organisations. The adoption of <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" target="_blank" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> into UK law amounted to slashing the time from 40 working days to 30 working days for a response. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/31623/what-is-a-subject-access-request" data-original-url="/data-protection/31623/what-is-a-subject-access-request">What is a subject access request?</a></p></div></div><p>When it comes to responding to SARs, there are several common areas of confusion – often regarding whether or not particular information counts as “personal data” or whether any exemption might apply. These themes include “do I have to provide every email which mentions them over the past 20 years?” and “our customer services rep called them a twerp – can I withhold this?”. There are more unusual queries, too, which raise lesser-known aspects of the rules. </p><p>Where there’s no obvious answer to such questions, it may be helpful to open up a dialogue with the requestor to find a solution together, such as how they might identify themselves. You should also keep clear records of analysis and conclusions, including when you apply exemptions, and how you’ve balanced corporate interests with transparency for individuals. Although many SARs may seem straightforward, there are nuances in how the law is applied, which businesses need to remain on top of.</p><h2 id="do-ip-addresses-count-as-personal-data">Do IP addresses count as personal data?</h2><p>A company received a request from an individual to access information associated with an <a href="https://www.itpro.com/infrastructure/network-internet/358606/static-ip-vs-dynamic-ip-whats-the-difference" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/358606/static-ip-vs-dynamic-ip-whats-the-difference">internet protocol (IP)</a> address, which the requestor said was assigned to their computer. The question posed to me by the company was: do we need to provide this information?</p><p>A person has a right to access to personal data, which means information relating to an identified or identifiable individual. Someone can be identified by reference to an “online identifier”, which includes <a href="https://www.itpro.com/security/361576/what-are-cookies" target="_blank" data-original-url="https://www.itpro.com/security/361576/what-are-cookies">cookie identifiers</a> and IP addresses. So, in theory, information associated with an IP address – such as logs of access to a website, or behavioural advertising profiles – could be <a href="https://www.itpro.com/business-strategy/data-insights/354179/how-much-is-your-data-worth-and-can-you-turn-it-into-cash" target="_blank" data-original-url="https://www.itpro.com/business-strategy/data-insights/354179/how-much-is-your-data-worth-and-can-you-turn-it-into-cash">personal data</a>. </p><p>But it isn’t as simple as that. An organisation may or may not use IP addresses in a way that is intended to identify or impact specific individuals. They may automatically be collected by its systems, but either not reviewed, or only used for gathering aggregated statistics on website visitors. An organisation may also be unable to link the identity of someone making a SAR to the personal data associated with the IP address. So, if you receive a message from me asking for logs of my access to your website – which requires no credentials to access – can you be sure which IP addresses and therefore which logs relate to me? </p><h2 id="how-do-you-identify-the-individual-making-a-sar">How do you identify the individual making a SAR?</h2><p>There’s an interesting and often overlooked provision of the UK GDPR under Article 11: if the purposes for which personal data is processed don’t require the identification of an individual, the organisation doesn’t have to maintain additional information to identify them. Furthermore, if the organisation can demonstrate it cannot identify them, the right of access, together with other rights of individuals, doesn’t apply. There’s an exception, however, If the individual provides additional information to identify themselves. They will then have a right to access their data. </p><p>Even where Article 11 doesn’t apply, where an organisation has reasonable doubts as to a requestor’s identity, Article 12(6) allows it to ask them for additional information to confirm their identity (before addressing the request). </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/367430/data-protection-by-design-isnt-just-a-buzzphrase" data-original-url="/policy-legislation/data-protection/367430/data-protection-by-design-isnt-just-a-buzzphrase">Data protection by design isn’t just a buzzphrase you can ignore</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gsrHFWG5yYnV7wtojcUNZY" name="gsrHFWG5yYnV7wtojcUNZY.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gsrHFWG5yYnV7wtojcUNZY.jpg" mos="https://cdn.mos.cms.futurecdn.net/gsrHFWG5yYnV7wtojcUNZY.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>In unpredictable times, a data strategy is key</strong></p><p class="fancy-box__body-text">Data processes are crucial to guide decisions and drive business growth</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/367519/in-unpredictable-times-a-data-strategy-is-key" data-original-url="/business-strategy/data-insights/367519/in-unpredictable-times-a-data-strategy-is-key">FREE DOWNLOAD</a></p></div></div><p>On an aside, where there is an issue with identifying someone making a request, I often hear a stock response of “we shall request a copy of the individual’s passport and proof of address”. Indeed, a passport contains several potential identifiers; full name, image, passport number, date of birth, and proof of address would mean you now know where the person lives. But how would that actually help you if your only dealings with them are online, and the records you hold do not include any of the same identifiers? What you have achieved is the collection of additional (possibly more sensitive) personal data leading to greater <a href="https://www.itpro.com/policy-legislation/data-protection/367430/data-protection-by-design-isnt-just-a-buzzphrase" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/367430/data-protection-by-design-isnt-just-a-buzzphrase">data protection</a> risks in handling it. Identification checks need to be tailored to the context of your relationship with an individual.</p><p>Whilst the company in question did hold certain records by reference to an IP address, it could not at that stage be sure the IP address uniquely identified the person making the request. It needed to consider, in relation to the records held, whether it was in a position to identify an individual, and whether the requestor could provide additional information to enable their identification. </p><h2 id="exemptions-to-the-right-of-access">Exemptions to the right of access</h2><p>Another organisation received a SAR from someone looking for information on decisions made about them. Opinions and decisions about someone are that person’s personal data, as the information “relates to” them. Information about reasons for a decision may also be personal data, again to the extent it relates to the specific individual. </p><p>However, the organisation was concerned that releasing all records concerning relevant decisions would reveal confidential and proprietary information about its decision-making techniques. So the question to me was whether it could apply any exemptions. </p><p>The bulk of the exemptions can be found in schedules 2 to 4 of the UK <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act 2018</a>, which complements the UK GDPR. One that pops up a lot is “management forecasts”. This applies where data is used for the purpose of management planning, for example in relation to redundancies, and provision of that data would be likely to prejudice the conduct of the business, which didn’t apply in this case. </p><h3 class="article-body__section" id="section-is-intellectual-property-exempt-from-sars"><span>Is intellectual property exempt from SARs?</span></h3><p>One exception relating to SARs sits under Article 15(4): “The right to obtain a copy… shall not adversely affect the rights and freedoms of others.” The data protection rights of other individuals most commonly spring to mind, but this can also refer to “trade secrets or intellectual property and in particular the copyright protecting the software”.</p><p>The purpose of the right of access is transparency, and exemptions are there to protect other businesses or public interests, but they shouldn’t be overused. It’s also important the application of Article 15(4) requires a balancing test between the requesting individual’s right of access to data, IP or rights of the other party. Just because another right exists does not mean that Article 15(4) automatically applies – in some cases the importance of providing access to personal data overrides the other right. In addition, perhaps curiously, it is an exception to the right to receive a copy of the data (under Article 15(3)), but not a general exemption to the right of access. </p><p>Taking all this into account, companies should not take an all-or-nothing approach. They need to assess how much personal data they can still provide, and how they can provide it, without unreasonably affecting other rights. A company could, for example, send reduced sets of data, or redact or extract data from records. </p><h3 class="article-body__section" id="section-what-do-the-data-regulators-say-about-intellectual-property"><span>What do the data regulators say about intellectual property?</span></h3><p>The reference to intellectual property rights in the UK GDPR is another frequently overlooked provision. Indeed, the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> guidance on exemptions doesn’t seem to mention it at all. It is touched on, however, within the European Data Protection Board (EDPB) guidelines on the equivalent right of access under the EU GDPR. They give an example of a gamer being denied access to a gaming platform due to allegations of cheating, detected by anti-cheating software. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/354179/how-much-is-your-data-worth-and-can-you-turn-it-into-cash" data-original-url="/business-strategy/data-insights/354179/how-much-is-your-data-worth-and-can-you-turn-it-into-cash">How much is your data worth? And can you turn it into cash?</a></p></div></div><p>The gamer makes a SAR, and requests information about the reasons for the decision. The gaming platform should provide some information about the alleged cheating – such as dates and times, what was detected – but may be able to withhold information concerning the technical operation of the anti-cheat software, if this is a trade secret and, presumably, to protect copyright. </p><p>Another example in the guidelines relates to a company’s proprietary techniques for a medical assessment. If the person makes a SAR, the company may be able to withhold information about the results of the assessment as it may reveal its techniques. </p><p>Regarding the original query, the organisation therefore needed to think about a few things: </p><ol><li>What specific content concerning decisions was the requestor’s personal data, and which decision-making techniques may be revealed by sharing this data</li><li>Whether its decision-making techniques gave rise to intellectual property rights (to be assessed under intellectual property laws</li><li>If so, how to balance those rights with the requestor’s right of access, and then to reach a conclusion: what personal data could and should still be shared, and how?</li></ol><h3 class="article-body__section" id="section-what-about-automated-decision-making"><span>What about automated decision-making?</span></h3><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xUYTPgzbsUuwKthpREks9Z" name="xUYTPgzbsUuwKthpREks9Z.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/xUYTPgzbsUuwKthpREks9Z.png" mos="https://cdn.mos.cms.futurecdn.net/xUYTPgzbsUuwKthpREks9Z.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Uncover new insights with your data in the cloud</strong></p><p class="fancy-box__body-text">React faster and anticipate change - A guide and assessment for SMBs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-management/369918/uncover-new-insights-with-your-data-in-the-cloud" data-original-url="/data-insights/data-management/369918/uncover-new-insights-with-your-data-in-the-cloud">FREE DOWNLOAD</a></p></div></div><p>Since we’re talking about decision-making, though, that’s not everything. As well as giving individuals a right to access personal data, Article 15(1) UK GDPR requires information to be provided about solely <a href="https://www.itpro.com/automation/34592/what-is-robotic-process-automation" target="_blank" data-original-url="https://www.itpro.com/automation/34592/what-is-robotic-process-automation">automated decision-making</a>. This means decisions made by technological means without human involvement, such as automated credit scoring. </p><p>If these were taking place, the organisation must inform the requestor (amongst other matters) about the logic involved in those decisions. This does not necessarily mean sharing detailed algorithms, which may also prejudice intellectual property rights. But the information must be meaningful for the individual, to enable them to understand how the decision was made. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Latest Meta GDPR fine brings 12-month total to more than €1 billion ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/369806/latest-meta-fine-brings-12-month-total-more-than-1-billion</link>
                                                                            <description>
                            <![CDATA[ Meta was issued with two hefty GDPR fines for “forcing” users to consent to data processing ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2wE5LQ4WdcwzXPom7Zfi4x</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7YmNroW5rE5SnssCTdfc7M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jan 2023 13:07:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7YmNroW5rE5SnssCTdfc7M-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Meta Platforms signage outside the company&amp;#039;s headquarters in Menlo Park, California]]></media:description>                                                            <media:text><![CDATA[Meta Platforms signage outside the company&amp;#039;s headquarters in Menlo Park, California]]></media:text>
                                <media:title type="plain"><![CDATA[Meta Platforms signage outside the company&amp;#039;s headquarters in Menlo Park, California]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7YmNroW5rE5SnssCTdfc7M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta’s latest fines bring the total penalties incurred by the tech giant to more than €1 billion over the last 12 months. </p><p>On Wednesday 4 January, Ireland’s Data Protection Commission (DPC) imposed two sizeable fines on the social media giant totalling €390 million for GDPR violations. </p><p>A lengthy probe by the data protection watchdog found that Meta’s use of data across its Facebook and Instagram platforms was unlawful. </p><p>The DPC investigation was launched following complaints made by privacy campaigner <a href="https://www.itpro.com/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement" data-original-url="https://www.itpro.com/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement">Max Schrems</a> in 2018. The complaint argued that, in order to comply with the newly-implemented regulations, both platforms requested users click “I accept” to confirm they agreed to updated conditions for ad targeting purposes. </p><p>According to the DPC, this meant the social media company had “forced” user consent to data processing unless they left the social media platforms, resulting in a breach of privacy regulations. </p><p>An initial fine of €210 million was issued for <a href="https://www.itpro.com/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties" data-original-url="https://www.itpro.com/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties">GDPR</a> violations on Facebook, the DPC said, while a second €180 million fine was also related to breaches by Instagram.</p><p>In a <a href="https://www.dataprotection.ie/en/news-media/data-protection-commission-announces-conclusion-two-inquiries-meta-ireland">ruling</a> on Wednesday, the DPC said that Meta must also bring its data processing operations in line with GDPR requirements within three months. </p><p>Meta said it plans to appeal the ruling, and told <a href="https://www.cnbc.com/world/?region=world"><em>CNBC</em></a> that the decision will not result in a ban on personalised advertising on Meta platforms. </p><p>“The suggestions that personalised ads can no longer be offered by Meta across Europe unless each user’s agreement has first been sought is incorrect,” a spokesperson for the company said. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/369779/meta-to-pay-725-million-in-cambridge-analytica-lawsuit" data-original-url="/marketing-comms/social-media/369779/meta-to-pay-725-million-in-cambridge-analytica-lawsuit">Meta to pay $725 million in Cambridge Analytica lawsuit settlement</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/369762/metas-open-approach-metaverse-development-monopoly-concerns" data-original-url="/business/business-strategy/369762/metas-open-approach-metaverse-development-monopoly-concerns">Meta affirms 'open' approach to industry-wide metaverse development amid monopoly concerns</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/369609/unacceptable-data-scraping-lands-meta-228m-fine" data-original-url="/business/policy-legislation/369609/unacceptable-data-scraping-lands-meta-228m-fine">"Unacceptable" data scraping lands Meta a £228m data protection fine</a></p></div></div><p>“There has been a lack of regulatory clarity on this issue, and the debate among regulators and policymakers around which legal basis is most appropriated in a given situation has been ongoing for some time,” the statement added. </p><p>Forrester analyst <a href="https://www.forrester.com/blogs/meta-hit-with-fine-and-an-uncertain-advertising-future">Stephanie Liu warned</a> that if the ruling stands, however, Meta will likely be forced to “explicitly ask users for consent for behavioural advertising” - or find a workaround. </p><p>“It would also need processes, workflows, and capabilities to disable targeted advertising for users who don’t consent while also convincing advertisers that its properties are still worthy of their ad budgets,” Liu added. </p><h2 id="recurring-meta-fines">Recurring Meta fines </h2><p>This latest batch of fines marks the climax of a difficult 12 months for the social media giant. Across the past year, Meta has incurred more than €1 billion in fines from European regulators. </p><p>In November, the company was fined <a href="https://www.itpro.com/business/policy-legislation/369609/unacceptable-data-scraping-lands-meta-228m-fine" data-original-url="https://www.itpro.com/business/policy-legislation/369609/unacceptable-data-scraping-lands-meta-228m-fine">€265 million</a> by the DPC after a lengthy probe into a damaging data scraping incident. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4tEvunnhNH3hyoz8H9hNLe" name="4tEvunnhNH3hyoz8H9hNLe.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/4tEvunnhNH3hyoz8H9hNLe.jpg" mos="https://cdn.mos.cms.futurecdn.net/4tEvunnhNH3hyoz8H9hNLe.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Six myths of SIEM</strong></p><p class="fancy-box__body-text">Things have changed when it comes to SIEM solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/367048/six-myths-of-siem" data-original-url="/security/security-information-and-event-management-siem/367048/six-myths-of-siem">FREE DOWNLOAD</a></p></div></div><p>The 17-month inquiry found that personal data belonging to more than 533 million Facebook users was publicly available online, and had been scraped from the platform over a 15-month period between May 2018 and September 2019. </p><p>Two months prior, in September 2022, regulators also imposed a <a href="https://www.itpro.com/security/privacy/368989/instagram-slapped-with-eu405-million-gdpr-fine-over-breaches" data-original-url="https://www.itpro.com/security/privacy/368989/instagram-slapped-with-eu405-million-gdpr-fine-over-breaches">€405 million fine</a> after Instagram was found to have mishandled teenagers’ personal information. </p><p>This consistent wave of regulatory crackdowns has prompted the tech giant to set aside a €2bn (£1.7bn) fund to accommodate for penalties expected across 2023, according to reports from the <a href="https://www.irishtimes.com/business/2022/12/06/eu-privacy-regulators-instruct-irish-dpc-to-revise-decision-in-meta-rulings"><em>Irish Times</em></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft's EU Data Boundary will begin staggered rollout in January 2023 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/369720/microsofts-eu-data-boundary-rollout-january-2023</link>
                                                                            <description>
                            <![CDATA[ Public sector and commercial customers will be the first to benefit when the rollout begins on 1 January across all of Microsoft's core services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6X2G6gVntb3FTbmW1cCLSM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Dec 2022 12:24:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of a Microsoft building]]></media:description>                                                            <media:text><![CDATA[View of a Microsoft building]]></media:text>
                                <media:title type="plain"><![CDATA[View of a Microsoft building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has announced the staggered rollout of its long-awaited EU Data Boundary solution will begin in January 2023.</p><p>The solution is expected to roll out first to public sector and commercial customers and aims to allow businesses to store and process their customer's data within the European Union (EU).</p><p>First <a href="https://blogs.microsoft.com/eupolicy/2021/05/06/eu-data-boundary">announced</a> last year, the data boundary builds on Microsoft’s existing EU data storage commitments. The data residency solution means that customer data will only be processed and accessed from the jurisdiction in which it originates. </p><p>Microsoft said this was developed using extensive customer feedback over the last 18 months. Engineering work to support the implementation of the solution began shortly after the announcement in May 2021. </p><p>When introduced on 1 January, the change will apply to all core services, including Azure, Microsoft 365, Power BI, and Dynamics 365. </p><p>“Beginning on 1 January 2023, Microsoft will offer customers the ability to store and process their customer data within the EU Data Boundary for Microsoft 365, Azure, Power Platform, and Dynamics 365,” the company said in a <a href="https://blogs.microsoft.com/eupolicy/2022/12/15/eu-data-boundary-cloud-rollout">statement</a>. </p><p>“With this release, Microsoft expands on local storage and processing commitments, greatly reducing data flows out of Europe, and building on our industry-leading data residency solutions.” </p><p>In later phases of its rollout, Microsoft also outlined plans to expand the solution to include the storage and processing of “additional categories of personal data”, including data provided when receiving technical support. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3AqyMeTacWD2fDQGnUCXJh" name="3AqyMeTacWD2fDQGnUCXJh.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/3AqyMeTacWD2fDQGnUCXJh.png" mos="https://cdn.mos.cms.futurecdn.net/3AqyMeTacWD2fDQGnUCXJh.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>An end-to-end roadmap for SMB cloud migration</strong></p><p class="fancy-box__body-text">Future-proofing transformation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/smb/369666/an-end-to-end-roadmap-for-smb-cloud-migration" data-original-url="/business-strategy/smb/369666/an-end-to-end-roadmap-for-smb-cloud-migration">FREE DOWNLOAD</a></p></div></div><p>At present, Microsoft provides <a href="https://www.itpro.com/cloud/367935/best-cloud-computing-services-in-2022" data-original-url="https://www.itpro.com/cloud/367935/best-cloud-computing-services-in-2022">cloud services</a> to customers in nearly every country in the world. In Europe specifically, the company has opened – and is currently building – <a href="https://www.itpro.com/strategy/29134/what-is-a-datacentre" data-original-url="https://www.itpro.com/strategy/29134/what-is-a-datacentre">data centres</a> in 17 data centre regions. The tech giant plans to build nine new additional regions in the coming years. </p><p>The rollout of the EU data boundary solution aims to support the regulatory requirements of customers across the EU and European Free Trade Association (EFTA), and follows long-running concerns over the <a href="https://www.itpro.com/policy-legislation/data-protection/356087/eu-fires-warning-shot-to-uk-over-post-brexit-us-data" data-original-url="https://www.itpro.com/policy-legislation/data-protection/356087/eu-fires-warning-shot-to-uk-over-post-brexit-us-data">flow of customer data</a> across international boundaries. </p><p>Julie Brill, Microsoft’s chief privacy officer told <em><a href="https://www.reuters.com/technology">Reuters</a></em> the data boundary solution will “make our customers feel more confident” and enable them to have “clear conversations with regulators on where their data is being processed as well as stored”. </p><h2 id="international-data-flows">International data flows </h2><p>Since the introduction of the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> in 2018, businesses globally have become increasingly concerned about the legality of international data flows, and operating across a wide variety of regulatory frameworks has presented challenges with regard to compliance. </p><p>The European Commission has been vocal in its intent to enforce regulatory requirements and is currently developing proposals to protect European user data during transferrals to the United States. </p><p>Similarly, in May 2021 the EU's data protection supervisor (EDPS) authority launched a probe into the European Commission’s use of <a href="https://www.reuters.com/technology">Microsoft 365</a> products amid concerns over <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31065/gdpr-compliance-checklist-is-your-organisation-gdpr" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31065/gdpr-compliance-checklist-is-your-organisation-gdpr">GDPR compliance</a>. </p><p>Mike Kiersey, EMEA head of sales engineering at Boomi, told <em>IT Pro</em> that ensuring the seamless flow of data is critical to business operations globally. As such, support for organisations to ensure compliance is a welcomed move. </p><p>“Data movement is happening more often in real-time and it has become crucial to successful business operations,” he said. “Therefore, the ability to have iniquitous access to data at speed is key for providers.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">What is GDPR? Everything you need to know, from requirements to fines</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties" data-original-url="/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties">ICO: The public sector isn’t getting 'an easier ride' with GDPR penalties</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system" data-original-url="/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system">Government reveals fresh replacement for GDPR will be a ‘bespoke, British’ system</a></p></div></div><p>Caroline Carruthers, CEO and co-founder at data consultancy Carruthers and Jackson, warned that the introduction of the EU data boundary “fundamentally makes data flow less efficient” and will not fully prevent personal information from being accessed in different jurisdictions.</p><p>“Data does not respect geography, and attempting to ringfence it will never give 100% protection to customers,” she said.</p><p>“Putting up data boundaries and restricting free flow of data is a regressive step for wider data transformation. Instead of trying to pull up the castle moat on European data, governments and multinationals should be pushing for global data standards to ensure enhanced security does not stifle data innovation.“</p><p>Microsoft said its cloud services “already comply with or exceed EU requirements”, adding that the introduction of the new <a href="https://www.itpro.com/policy-legislation/data-protection/359453/microsoft-to-give-eu-business-customers-greater-control" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359453/microsoft-to-give-eu-business-customers-greater-control">data boundary</a> will provide future benefits for the <a href="https://www.itpro.com/business-strategy/public-sector/361729/the-it-pro-podcast-whats-so-hard-about-public-sector-it" data-original-url="https://www.itpro.com/business-strategy/public-sector/361729/the-it-pro-podcast-whats-so-hard-about-public-sector-it">public sector</a> and commercial customers operating within the EU and EFTA, helping them to remain compliant. </p><p>In addition, as part of the rollout, the tech giant revealed plans to publish new data flow documentation to provide “transparent data insights” for customers whose services will be included in the boundary. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ "Unacceptable" data scraping lands Meta a £228m data protection fine  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/369609/unacceptable-data-scraping-lands-meta-228m-fine</link>
                                                                            <description>
                            <![CDATA[ The much-awaited decision follows the scraping of half a billion users' data and received unanimous approval from EU regulators ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gsxknFGZ8MzgWeykQ3uu3U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VqucWcMkRxEvWWaWDKZh9m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Nov 2022 12:55:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VqucWcMkRxEvWWaWDKZh9m-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Meta logo shown on a phone, in front of an orange to purple gradient bearing smaller versions of the logo]]></media:description>                                                            <media:text><![CDATA[The Meta logo shown on a phone, in front of an orange to purple gradient bearing smaller versions of the logo]]></media:text>
                                <media:title type="plain"><![CDATA[The Meta logo shown on a phone, in front of an orange to purple gradient bearing smaller versions of the logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VqucWcMkRxEvWWaWDKZh9m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta has been fined €265m (£228m) by the Irish Data Protection Commission (DPC), following a prolonged inquiry into a data scraping incident.</p><p>The DPC imposed a reprimand against Meta, leveraged the administrative fine against the firm, and ordered it to take specific remedial measures within a specific time frame in order to bring its processing of personal data into compliance with EU law. </p><p>The decision comes after a 17-month inquiry into the company, after it was discovered that <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">personal data</a> from the Facebook accounts of 533 million users was publicly available on a hacking forum.</p><p>This had been scraped from Facebook between May 2018 and September 2019 through the use of tools intended to link users to their friends using phone numbers.</p><p>As part of its decision, the DPC did not find that the incident constituted a hack, <a href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach%5D">data breach</a>, or security practice failing. In a <a href="https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-decision-in-facebook-data-scraping-inquiry">press release</a> on the decision, the DPC stated that the inquiry and decision process included “cooperation with all of the other data protection supervisory authorities within the EU”, and that all agreed on the final decision.</p><p>"Protecting the privacy and security of people’s data is fundamental to how our business works,” a Meta spokesperson told <em>IT Pro</em>. </p><p>“That’s why we have cooperated fully with the Irish Data Protection Commission on this important issue. We made changes to our systems during the time in question, including removing the ability to scrape our features in this way using phone numbers. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wnmQ9imps85axutghCiKXL" name="wnmQ9imps85axutghCiKXL.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/wnmQ9imps85axutghCiKXL.png" mos="https://cdn.mos.cms.futurecdn.net/wnmQ9imps85axutghCiKXL.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Five common data security pitfalls</strong></p><p class="fancy-box__body-text">Learn how to improve your security posture</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369383/five-common-data-security-pitfalls" data-original-url="/security/369383/five-common-data-security-pitfalls">FREE DOWNLOAD</a></p></div></div><p>“Unauthorised data scraping is unacceptable and against our rules and we will continue working with our peers on this industry challenge. We are reviewing this decision carefully.”</p><p>The decision has brought the total amount that Meta has paid in data privacy fines within Europe to €1 billion (£863,000), with the DPC having ordered Meta subsidiary <a href="https://www.itpro.com/security/privacy/368989/instagram-slapped-with-eu405-million-gdpr-fine-over-breaches" data-original-url="https://www.itpro.com/security/privacy/368989/instagram-slapped-with-eu405-million-gdpr-fine-over-breaches">Instagram to pay a record €405 million</a> in September for a violation of GDPR involving <a href="https://www.itpro.com/business-operations/31681/what-is-data-processing" data-original-url="https://www.itpro.com/business-operations/31681/what-is-data-processing">data processing</a> for the platform’s 13-17-year-old users. The commission found that children in this age range could set up business accounts, set to 'public' by default.</p><p>“Meta is on a losing streak,” said Sarah Coop, analyst at data and analytics company GlobalData.</p><p>“Privacy breaches damage consumer trust, which is already dwindling for Meta. Its central social media platform, Facebook, is struggling to attract younger users due to strong competition from other platforms like TikTok. The company has also reportedly lost $9.4 billion on its metaverse business unit and has recently restructured, laying off 11,000 employees.”</p><p>“GDPR fines are simply collateral damage for Big Tech. While fines can be large, at up to 4% of global turnover, most Big Tech consider it the cost of doing business. However, consumer confidence will be important for the metaverse, and cybersecurity breaches and data privacy fines further taint Meta’s already tarnished reputation.”</p><p>However, some in the industry have pointed out that the mishandling of personal data is far from a problem unique to Meta.</p><p>“Meta should not be the scapegoat of those worried about misuse of personal data,” said Paul Brucciana, cyber security advisor at WithSecure</p><p>“4.1 billion records leaked in the first 6 months of 2019 alone. In a recent poll of 1,000 US companies, nearly half (45%) claim they have faced a major data breach within the past five years. The situation is unlikely to be less grave anywhere else.”</p><p>In addition to following the decision made by the DPC, Meta has outlined a number of practices that it has already implemented in order to tackle data scraping on its platforms.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/368989/instagram-slapped-with-eu405-million-gdpr-fine-over-breaches" data-original-url="/security/privacy/368989/instagram-slapped-with-eu405-million-gdpr-fine-over-breaches">Instagram slapped with €405 million GDPR fine over breaches</a> General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369545/the-it-pro-podcast-how-secure-is-metaverse-tech" data-original-url="/security/369545/the-it-pro-podcast-how-secure-is-metaverse-tech">The IT Pro Podcast: How secure is metaverse tech?</a></p></div></div><p>The firm has employed tactics such as rate limiting to prevent scrapers from using platforms at an abnormal speed, automated tools for investigation, and hunting down datasets with the help of threat intelligence researchers.</p><p>Meta stated that users can tailor their privacy settings to limit the amount of data visible on their profile, which in turn reduces data misuse. </p><p>The fine comes amidst a record low for Meta’s finances. In October, the company’s <a href="https://www.itpro.com/business/business-strategy/369410/metas-earnings-are-cause-for-conern-and-2023-looks-even-bleaker" data-original-url="https://www.itpro.com/business/business-strategy/369410/metas-earnings-are-cause-for-conern-and-2023-looks-even-bleaker">earnings call painted a bleak picture</a>, with net income down 52% against a 19% surge in spending.</p><p>The firm’s commitment to developing <a href="https://www.itpro.com/business-strategy/collaboration/367376/into-the-metaverse-everything-we-learned" data-original-url="https://www.itpro.com/business-strategy/collaboration/367376/into-the-metaverse-everything-we-learned">metaverse</a> tech, driven in no small part by CEO Mark Zuckerberg, has led to record spending by the company on its Reality Labs division, with almost $10 billion allocated this year alone, and more locked in for 2023. </p><p>Since its earnings call, <a href="https://www.itpro.com/business-strategy/careers-training/369487/meta-cuts-11000-staff-citing-wrong-call-on-investment" data-original-url="https://www.itpro.com/business-strategy/careers-training/369487/meta-cuts-11000-staff-citing-wrong-call-on-investment">Meta has cut 11,000 staff</a> amidst calls by Zuckerberg for a more capital-efficient company. The firm has admitted that its growth has not hit the anticipated targets, and Zuckerberg has indicated that its current financial situation is down to a mixture of <a href="https://www.itpro.com/business/business-strategy/368496/why-businesses-should-invest-their-way-out-of-a-downturn" data-original-url="https://www.itpro.com/business/business-strategy/368496/why-businesses-should-invest-their-way-out-of-a-downturn">macroeconomic factors</a> and an overly-optimistic investment strategy. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ICO: The public sector isn’t getting 'an easier ride' with GDPR penalties ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties</link>
                                                                            <description>
                            <![CDATA[ The UK’s information commissioner outlines his new approach to regulation and why the most constructive punishments will always be favoured ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r3hbWmrfnQ6d4PFhzHpSUu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZoUhWWg8D3ay7Ce5Ux2vJR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Nov 2022 11:05:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZoUhWWg8D3ay7Ce5Ux2vJR-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up image of a smartphone with the ICO webpage displayed on screen]]></media:description>                                                            <media:text><![CDATA[A close up image of a smartphone with the ICO webpage displayed on screen]]></media:text>
                                <media:title type="plain"><![CDATA[A close up image of a smartphone with the ICO webpage displayed on screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZoUhWWg8D3ay7Ce5Ux2vJR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Information Commissioner's Office (ICO) has announced that it will be changing its approach to punishing data protection offences committed within the UK’s public sector.</p><p>Information Commissioner John Edwards said that the organisation’s regulatory approach will focus more on fixing the underlying issues and that issuing monetary penalties is ultimately counter-intuitive in many cases.</p><p>Citing an incident where he was recommended to fine an NHS Trust, Edwards told delegates at the National Association of Data Protection Officers (NADPO) annual conference on Tuesday that fining the Trust would have just harmed the quality of service given to patients, punishing them. </p><p>“That fine would have come directly from the money available to that service to deliver services to the victims of the UK GDPR non-compliance,” he said. “We would further punish the very victims whose rights we are there to uphold.”</p><p>The same ‘gentler’ approach will be applied across all areas of the public sector, not just the emergency or other critical services.</p><p>Issuing fines to organisations in central government is often also ineffective, Edwards said, and previous cases have shown little evidence to support the idea that fines lead to better outcomes or overall compliance. </p><p>The Cabinet Office was <a href="https://www.itpro.com/security/data-breaches/361732/ico-fines-cabinet-office-ps500000-for-new-year-honours-data-leak" data-original-url="https://www.itpro.com/security/data-breaches/361732/ico-fines-cabinet-office-ps500000-for-new-year-honours-data-leak">fined £500,000 by the ICO in 2021</a> for the 2019 New Year’s Honours breach in which more than 1,000 individuals’ had their home addresses leaked.</p><p>It was decided the most effective course of punishment was to reduce this fine to £50,000 after an appeal, given the economic challenges the <a href="https://www.itpro.com/business-strategy/public-sector/361729/the-it-pro-podcast-whats-so-hard-about-public-sector-it" data-original-url="https://www.itpro.com/business-strategy/public-sector/361729/the-it-pro-podcast-whats-so-hard-about-public-sector-it">public sector</a> currently faces.</p><p>The Department for Education (DfE) most recently escaped a monetary penalty for its incident in November which saw school pupils’ learning records used by gambling companies to conduct age-verification checks.</p><p>Edwards said this would usually garner a £10m fine but the new approach took into consideration that the DfE enacted all the required changes to prevent future data protection breaches of this kind before <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">the ICO</a> could even issue the instruction to do so. </p><p>As a result, the department received just a formal reprimand and no fine, a punishment the ICO deemed appropriate given the department’s proactivity in remediating the issues.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Crmp8gk4ybzxEU2BqA5dcS" name="Crmp8gk4ybzxEU2BqA5dcS.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/Crmp8gk4ybzxEU2BqA5dcS.png" mos="https://cdn.mos.cms.futurecdn.net/Crmp8gk4ybzxEU2BqA5dcS.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Data governance and privacy for data leaders</strong></p><p class="fancy-box__body-text">Create your ideal governance and privacy solution</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/369356/data-governance-and-privacy-for-data-leaders" data-original-url="/business-strategy/data-insights/369356/data-governance-and-privacy-for-data-leaders">FREE DOWNLOAD</a></p></div></div><p>“Some commentators have suggested this might be a sign of weakness, or us ‘going easy’ on government. It's not,” said Edwards at the conference.</p><p>“My job is to make sure we’re working in the areas that will have the greatest impact. This doesn’t mean always reaching for the most flashy, headline-grabbing action that comes after the fact; sometimes it’s that behind-the-scenes work, the guidance and advice that we can offer businesses to encourage compliance and to help their understanding of the law and their obligations under it."</p><p>Monetary penalties will be reserved for organisations that have the potential to harm the most people. Edwards pointed to the recent fines against catalogue retailer Easylife - one worth £130,000 for “predatory marketing calls” and another worth £1.35 million for profiling customers before illegally calling them.</p><p>This is an example, Edwards said, of a case where fines can promote compliance - hurting money-making enterprises by impeding their money-making potential.</p><h2 id="further-regulatory-changes">Further regulatory changes</h2><p>Another change to Edwards’ approach is to begin publishing all reprimands to the ICO’s website, “unless there is a good reason not to” - something it currently does not do.</p><p>This is for the purposes of promoting accountability and transparency - the public and wider economy should be aware of any transgressions and why the ICO issued the punishment it chose.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/361732/ico-fines-cabinet-office-ps500000-for-new-year-honours-data-leak" data-original-url="/security/data-breaches/361732/ico-fines-cabinet-office-ps500000-for-new-year-honours-data-leak">Cabinet Office fined £500,000 for New Year Honours data leak</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system" data-original-url="/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system">Government reveals fresh replacement for GDPR will be a ‘bespoke, British’ system</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/business-communications/368514/ico-calls-for-gov-review-into-use-of-whatsapp-and-others" data-original-url="/marketing-comms/business-communications/368514/ico-calls-for-gov-review-into-use-of-whatsapp-and-others">ICO calls for gov review into use of WhatsApp and other private communication channels</a></p></div></div><p>Non-monetary enforcement actions available to the ICO, aside from fines, include warnings (when violations are likely to be committed), reprimands (formal expressions of disapproval towards conduct when the threshold for a fine hasn’t been met), and compliance orders (instructions to offenders that changes need to be made to re-establish <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31065/gdpr-compliance-checklist-is-your-organisation-gdpr" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31065/gdpr-compliance-checklist-is-your-organisation-gdpr">compliance</a>).</p><p>Edwards also said he wanted the regulatory process to be more predictable and certain, and the increased emphasis on transparency would help inform organisations what the law requires of them.</p><p>In addition, the new approach aims to be more flexible. Tied with the ideas of certainty and predictability, Edwards believes that organisations should be free to <a href="https://www.itpro.com/technology/31754/what-is-disruptive-innovation" data-original-url="https://www.itpro.com/technology/31754/what-is-disruptive-innovation">innovate their products and services</a> with confidence that they still meet compliance criteria.</p><p>The ICO will soon be launching a new advice service dedicated to supporting organisations with their planned innovations in areas to support further investment, like new business models.</p><p>“Our advice service will offer direct, fast-paced answers and support to those looking to move quickly and innovate within the guardrails of the law,” he said. “This will do more to improve outcomes for the consumers of those services than aggressive regulatory action after the fact would, after the harm has been done. ”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Government reveals fresh replacement for GDPR will be a ‘bespoke, British’ system ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system</link>
                                                                            <description>
                            <![CDATA[ The DCMS is to be co-designed with businesses with the aim of streamlining data protection, but some already call the change unneeded ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tPYnvPSFow5ursYoF9RUAU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aBTpcKUdCeKBcqaMwY6mAC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Oct 2022 11:12:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aBTpcKUdCeKBcqaMwY6mAC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Minister of state for DCMS, Michelle Donelan, giving a speech at a podium whilst at the Conservative Party Conference 2022]]></media:description>                                                            <media:text><![CDATA[Secretary of state for DCMS, Michelle Donelan, giving a speech at a podium whilst at the Conservative Party Conference 2022]]></media:text>
                                <media:title type="plain"><![CDATA[Secretary of state for DCMS, Michelle Donelan, giving a speech at a podium whilst at the Conservative Party Conference 2022]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aBTpcKUdCeKBcqaMwY6mAC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The government has made fresh comments confirming its plans to scrap GDPR and instead create a new system of data regulation for the UK based on "common sense".</p><p>The new regulation will be 'intensive', said the secretary of state for digital, culture, media and sport (DCMS) Michelle Donelan, who did not offer any specific details about how the regulation may take shape.</p><p>“Our plan will protect consumer privacy, and keep their data safe, whilst retaining our data adequacy, so that businesses can trade freely,” said Donelan, who formally announced the move at the Conservative Party Conference, currently taking place in <a href="https://www.itpro.com/business-strategy/startups/361184/west-midlands-uk-fastest-growing-tech-hub" data-original-url="https://www.itpro.com/business-strategy/startups/361184/west-midlands-uk-fastest-growing-tech-hub">Birmingham</a>.</p><p>“Our new data protection plan will focus on growth, on common sense, on helping to prevent losses from <a href="https://www.itpro.com/security/cyber-warfare/367342/russian-cyber-attacks-should-your-business-worry" data-original-url="https://www.itpro.com/security/cyber-warfare/367342/russian-cyber-attacks-should-your-business-worry">cyber attacks</a> and <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach" data-original-url="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach">data breaches</a>, while also protecting data privacy.”</p><p>Citing the abundance of 'red tape' as a primary goal for enacting the new regulation, Donelan quoted a DCMS survey in which 50% of polled businesses said that the General Data Protection Regulation (GDPR) had led to "excessive caution" amongst their workforce when handling data.</p><p>Donelan emphasised that the new system will be co-designed with businesses, and cited the example of countries that have achieved data adequacy without implementing GDPR, such as Israel, Japan, South Korea, Canada and New Zealand.</p><p>However, many familiar with GDPR and wider data regulation have already voiced their criticism of the idea, which is being billed as unnecessary.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FaB2FMpWMfQo5Z9ruoKGdb" name="FaB2FMpWMfQo5Z9ruoKGdb.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/FaB2FMpWMfQo5Z9ruoKGdb.png" mos="https://cdn.mos.cms.futurecdn.net/FaB2FMpWMfQo5Z9ruoKGdb.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Just enough data governance</strong></p><p class="fancy-box__body-text">Building program momentum and scale with agility</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-governance/369172/just-enough-data-governance" data-original-url="/policy-legislation/data-governance/369172/just-enough-data-governance">FREE DOWNLOAD</a></p></div></div><p>“I get really annoyed at this,” wrote former Conservative MEP Lord Kirkhope, in a <a href="https://twitter.com/LordKirkhope/status/1577027505424576512">tweet</a>.</p><p>“The so-called “EU GDPR” was actually partly written by me and other UK MEPs and is understood and accepted Internationally. It’s [sic] “proportionality” provisions were my idea. Leave it alone!”</p><p>Chair of the Standards and Privileges Committee Chris Bryant MP also pointed out that new regulation could end up not only giving <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30326/what-is-a-data-protection-officer" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/30326/what-is-a-data-protection-officer">data protection officers</a> even more work, but also costing businesses more.</p><p>“This is madness,” he <a href="https://twitter.com/RhonddaBryant/status/1577005619072335872">tweeted</a> in response to the announcement.</p><p>“UK companies will still have to abide by GDPR if they want any online business in the European Union (as other non-EU companies already do). So UK divergence will simply mean UK double costs.”</p><p>The government had announced plans earlier in 2022 to replace the UK’s implementation of the GDPR with the <a href="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr">Data Reform Bill</a>, which was intended to cut “red tape and pointless paperwork” and decrease the steps needed to use data in scientific research.</p><p>Progress on these plans was put on hold as prime minister Liz Truss built her own cabinet this summer. It appears this new legislation will take its place</p><p>The UK follows the regulatory framework of the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act (DPA) 2018</a>, which ensures that the UK retains data adequacy on the collection, processing, and storage of data and sets out the role of the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/google-android/367632/gdpr-slowing-innovation-in-the-android-app-market-research-claims" data-original-url="/mobile/google-android/367632/gdpr-slowing-innovation-in-the-android-app-market-research-claims">GDPR “slowing innovation” in the Android app market, research claims</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/368684/why-the-uk-is-dragging-its-feet-on-regulating-big-tech" data-original-url="/business/policy-legislation/368684/why-the-uk-is-dragging-its-feet-on-regulating-big-tech">Why the UK is dragging its feet on regulating big tech</a> General Data Protection Regulation (GDPR)</p></div></div><p>After January 2021, the UK also implemented its own regulations based on GDPR, known as the UK GDPR, to maintain adequacy whilst making some changes to the rights and obligations around processing personal data that are local to the UK.</p><p>The DPA 2018 works in tandem with, and occasionally provides exemptions for, the UK GDPR such as for law enforcement.</p><p>This is essential for UK businesses, as it ensures that sufficient <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection policies</a> are enforced, whilst keeping the UK compliant with regulations that let companies continue to trade with and operate in the EU. Without EU-compliant data protection, UK firms could not collect or process EU data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Your ultimate guide to the UK’s International Data Transfer Agreement (IDTA) ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/368849/guide-to-international-data-transfer-agreement-idta</link>
                                                                            <description>
                            <![CDATA[ If any of your data moves overseas – and most business data does – then you need to keep on top of the rules ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ciewTco9VMZeLG6k3r1fz1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HZxAVK3x5EMn6UQm7V3CJ4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Aug 2022 07:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Olivia Whitcroft ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HZxAVK3x5EMn6UQm7V3CJ4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of data beamed from the UK to the rest of the world]]></media:description>                                                            <media:text><![CDATA[Graphic of data beamed from the UK to the rest of the world]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of data beamed from the UK to the rest of the world]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HZxAVK3x5EMn6UQm7V3CJ4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It’s tricky writing articles about international data transfers. No sooner do you put down your figurative pen, than someone goes and changes the rules. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill" data-original-url="/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill">Why does the UK government want to replace GDPR with the Data Reform Bill?</a></p></div></div><p>Much has changed since I last wrote about the subject. First, the EU finalised its much-needed new <a href="https://www.itpro.com/policy-legislation/data-protection/359427/ico-devising-bespoke-uk-mechanism-for-global-data-sharing" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359427/ico-devising-bespoke-uk-mechanism-for-global-data-sharing">standard contractual clauses (SCCs)</a> for transfers of <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">personal data</a> out of the EU. Then it <a href="https://www.itpro.com/policy-legislation/data-protection/358674/eu-grants-the-uk-provisional-data-adequacy-status" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/358674/eu-grants-the-uk-provisional-data-adequacy-status">approved the UK data protection regime as “adequate”</a>, a mere whisker before the deadline of the end of June 2021.</p><p>Fresh with its adequacy decision from the EU, the UK started pumping out consultations on ways to change UK data protection law and guidance, and depart from consistency with EU law, in the form of the <a href="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill">Data Reform Bill</a>. International transfer issues formed a big part of these consultations. Most importantly, the UK’s new International Data Transfer Agreement (IDTA) came into force on 21 March 2022. </p><h2 id="when-did-the-eu-s-new-sccs-come-into-force">When did the EU’s new SCCs come into force? </h2><p>The EU SCCs for cross-border transfers were finalised on 4 June 2021. This is the most popular way to send personal data from the EU to a ‘third country’. EU organisations swiftly started updating their transfer contracts, with a deadline of 27 September 2021 to stop using old SCCs for new data transfers. </p><p>However, the UK didn’t allow the use of new EU SCCs for transferring data from the UK. British organisations were temporarily left with very limited ways to legitimise data transfers other than the out-of-date SCCs. Global organisations, including <a href="https://www.itpro.com/business/policy-legislation/368684/why-the-uk-is-dragging-its-feet-on-regulating-big-tech" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/368684/why-the-uk-is-dragging-its-feet-on-regulating-big-tech">big tech companies</a> transferring data to the US, needed to use different SCCs for data travelling from the EU to those used for data travelling from the UK. This was undoubtedly a good exercise in mapping out data flows, and finding tailored solutions, but again pointed to the fact the UK approach was soon expected to change. </p><h2 id="how-does-the-uk-s-data-adequacy-agreement-fit-into-the-equation">How does the UK’s data adequacy agreement fit into the equation?</h2><p>The EU Commission’s adequacy decision for the UK arrived on 28 June 2021 – just in time – as 30 June was the final day of the “bridge” allowing personal data to flow without additional safeguards. It was a huge relief. Although the ICO recommended organisations put in place a backup plan, many had put faith in the adequacy decision coming through.</p><p>This agreement, however, excludes data transferred to the UK for immigration control, which was one of the sticking points in the debate, as UK law exempts organisations from providing certain data protection rights. The decision also has an expiry date of 27 June 2025, and could be repealed before then if the UK deviates too far from GDPR.</p><h2 id="how-does-the-uk-s-international-data-transfer-agreement-work">How does the UK’s International Data Transfer Agreement work?</h2><p>The IDTA, prepared by the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> came into force on 21 March 2022. UK organisations can now escape the clutches of the old SCCs, but they’re still available for contracts concluded before 21 September 2022.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">What is the Information Commissioner’s Office (ICO)?</a></p></div></div><p>As an alternative, the ICO has produced an “addendum” to the new EU SCCs. This converts them to be suitable for transfers from the UK (rather than the EU) and reflects the requirements of UK law. The addendum may be useful for global organisations looking for a consistent set of clauses for transfers from the EU and the UK, or those unwilling to adapt to new provisions. On the other hand, the new IDTA is a standalone document, has more of a UK style, and may be easier to understand and put into practice. </p><h3 class="article-body__section" id="section-what-should-organisations-look-out-for"><span>What should organisations look out for?</span></h3><p>Organisations using the IDTA need to understand their data flows, first and foremost. Full details of the parties and transfers must be included in tables at the top. This includes descriptions of data types, data subjects, security requirements and any extra protections arising from transfer risk assessments.</p><p>The terms cater for different types of transfer (as do the new EU SCCs), including controller to controller, controller to processor, processor to sub-processor, and processor to controller. There are then some provisions that apply to all transfers, and some that apply only to specified types. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tmoVjhSAkMS3UPrt84pH79" name="tmoVjhSAkMS3UPrt84pH79.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/tmoVjhSAkMS3UPrt84pH79.png" mos="https://cdn.mos.cms.futurecdn.net/tmoVjhSAkMS3UPrt84pH79.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Evaluating modern enterprise storage</strong></p><p class="fancy-box__body-text">Dell EMC PowerStore is modern enterprise storage designed to address the needs of our new era</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/it-infrastructure/368837/evaluating-modem-enterprise-storage" data-original-url="/business-strategy/it-infrastructure/368837/evaluating-modem-enterprise-storage">FREE DOWNLOAD</a></p></div></div><p>The IDTA also envisages separate “linked agreements”, including data sharing or <a href="https://www.itpro.com/business-operations/31681/what-is-data-processing" target="_blank" data-original-url="https://www.itpro.com/business-operations/31681/what-is-data-processing">data processing</a> agreements. This means the transfer agreement can focus on transfer issues, and doesn’t need to address all data protection issues associated with the parties’ relationship, such as requirements under UK GDPR for contracts with a processor.</p><p>The majority of the clauses are mandatory, so organisations using the IDTA should generally use them as they are. However, practical changes are permitted, such as to make the agreement multi-party, where needed.</p><p>To assist in protecting data protection rights, data subjects and the ICO may bring claims against the parties for breach of the terms. </p><h2 id="how-did-different-consultations-impact-the-international-data-transfer-agreement-idta">How did different consultations impact the International Data Transfer Agreement (IDTA)?</h2><p>Alongside its consultation on the IDTA in August 2021, the ICO consulted on updates to its international data transfer guidance, together with a transfer risk assessment and tool. The UK government, in September 2021, also published a paper called Data: A new direction to consult on reforms to data protection legislation. Chapter 3 of this discusses reducing barriers to data flows. </p><h3 class="article-body__section" id="section-assessing-data-transfer-risks"><span>Assessing data transfer risks</span></h3><p>Firstly, the UK government recognises that assessing data transfer risks isn’t easy. Since <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" target="_blank" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">the <em>Schrems II</em> court decision in July 2020</a>, all organisations, large and small, have been required to do just this. I advise several small companies using cloud-based technology, which involves data transfers outside the UK. When I explain to my clients that they must research and assess the risks of such transfers, and then discuss this with giants such as Amazon, Google and Microsoft, I receive glazed and confused looks that tell me I am crazy.</p><p>Now, of course, just because an organisation is small, that doesn’t mean there are no data processing and transfer risks. Dispensing altogether with risk assessments, therefore, would not be a good solution. But the government says it intends to apply proportionality in developing transfer mechanisms, and to provide more practical support for organisations in assessing risks.</p><h3 class="article-body__section" id="section-exempting-reverse-transfers"><span>Exempting reverse transfers</span></h3><p>Another legislative proposal that my clients may welcome is exempting “reverse transfers” from the rules. Let’s say a UK company is providing add-on services to customers of an Australian company. The Australian company sends customer details to the UK company (in line with Australian data transfer rules). The UK company then needs to confirm some of these details, before sending them back to the Australian company. Currently, UK data transfer rules would kick in, creating an additional burden, when this is information which the Australian company already holds and sent to the UK in the first place. Under the proposals, the transfer rules would not capture sending data back to the originating entity. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="/data-protection/28177/data-protection-policies-and-procedures">Data protection policies and procedures</a></p></div></div><p>On a similar note, the ICO proposes that where a UK processor has been appointed by a controller outside the UK (which isn’t otherwise subject to UK data protection law), the transfer of data from the processor to the controller would not be a restricted transfer. For example, if a US company appoints a UK company to manage payroll on its behalf, the UK company would not then need to apply UK transfer rules each time payslips are sent over to the US company. This would also assist UK processors to stay competitive when pitching for work against providers local to the controller.</p><h3 class="article-body__section" id="section-where-can-the-guidance-improve"><span>Where can the guidance improve?</span></h3><p>The ICO’s guidance, and a point it consulted on, is that transfers are only restricted between legal entities. This includes transfers to group entities, but not to your own staff in another country. I’d like to see more clarity on whether this also excludes transfers to the data subjects themselves. Another proposal is that a restricted transfer is made by the party authorising it, which does not necessarily follow the data flow. This could ease (though not erase) the burden on small companies raised above; if a UK company uses a <a href="https://www.itpro.com/cloud/32167/our-5-minute-guide-to-enterprise-cloud-computing" target="_blank" data-original-url="https://www.itpro.com/cloud/32167/our-5-minute-guide-to-enterprise-cloud-computing">UK cloud provider</a> that appoints a sub-processor in the US, the cloud provider makes the restricted transfer. My view is that this should also work the other way around: if the UK company directs the cloud provider to transfer data directly to an overseas recipient, the UK company makes the restricted transfer.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9exnyaj6XxZMJPE3sGkDPB" name="9exnyaj6XxZMJPE3sGkDPB.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/9exnyaj6XxZMJPE3sGkDPB.png" mos="https://cdn.mos.cms.futurecdn.net/9exnyaj6XxZMJPE3sGkDPB.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Go ahead, dream big: The Dell EMC PowerVault ME4 platform</strong></p><p class="fancy-box__body-text">Delivering fast, affordable storage, optimised for the big plans of growing businesses</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/server-storage/368833/go-ahead-dream-big-the-dell-emc-powervault-me4-platform" data-original-url="/infrastructure/server-storage/368833/go-ahead-dream-big-the-dell-emc-powervault-me4-platform">FREE DOWNLOAD</a></p></div></div><p>The government is also proposing to allow repetitive use of derogations to transfer rules. Even though it’s generally accepted that use of derogations should be a last resort, sometimes the situation boils down to them being the best option. But UK GDPR recitals indicate that some are only available where the transfer is “occasional”. For example, the derogation for transfers that are necessary for performing a contract with the data subject could not currently be used if the transfers are repetitive. </p><p>A final point is that the government refers to an “ambitious programme of adequacy assessments”. Since Brexit, the jurisdictions that the UK deems adequate mirror those of the EU’s adequacy decisions, with the addition of Gibraltar, which isn’t covered by the EU’s adequacy decision for the UK. </p><h3 class="article-body__section" id="section-where-do-we-go-from-here"><span>Where do we go from here?</span></h3><p>On the face of it, these proposals seem sensible and helpful for many UK organisations. Though, if the UK creeps away from EU data protection law, this leads to the question of whether the UK’s regime will continue to be deemed adequate by the EU.</p><p>Both consultations ended in 2021. The ICO and the government are building up my excitement with signals that full outcomes will be published soon. On a final note, the US and the EU Commission agreed, in principle, a <a href="https://www.itpro.com/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement" target="_blank" data-original-url="https://www.itpro.com/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement">new framework for trans-Atlantic data flows</a> to replace the previous <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" target="_blank" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a>. The UK may not be jumping on board, though, as it’s exploring its own data adequacy partnership with the US. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ​​What is AdTech and why is it at the heart of a regulation storm? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation</link>
                                                                            <description>
                            <![CDATA[ The UK data regulator has come under heavy fire for consistently delaying much-needed action, privacy groups say ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hRFhxsc8CNu8chZ1QMCG9p</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U6RgpMswYmitjUxYBECVxh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Aug 2022 09:10:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Carly Page ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/haaytLZQLzJxCzMHFEeyiZ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U6RgpMswYmitjUxYBECVxh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Illustration showing somebody clicking on an ad and coins coming out]]></media:description>                                                            <media:text><![CDATA[Illustration showing somebody clicking on an ad and coins coming out]]></media:text>
                                <media:title type="plain"><![CDATA[Illustration showing somebody clicking on an ad and coins coming out]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U6RgpMswYmitjUxYBECVxh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Before the advent of the internet, advertising was a complex process that required a lot of time and effort, and was often a luxury that was only accessible to the biggest, most successful companies.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/digital-marketing/367745/third-party-cookie-phase-out-adtech-apocalypse" data-original-url="/marketing-comms/digital-marketing/367745/third-party-cookie-phase-out-adtech-apocalypse">The cookie phase-out might precede an AdTech apocalypse</a></p></div></div><p>Thanks to the explosion of e-commerce, the industry saw its first major shake-up in the 1990s with the advent of 480x60 banner ads that advertisers could choose to display on specific websites. This remained a manual process, though, and involved researching, checking metrics, and choosing which websites would bring the maximum return on investment (ROI) for advertisers.</p><p>The second major transformation came later that decade with the arrival of the first ad server software that would, as its name suggests, automatically serve ads. This software, which later became the Google Ad Manager, saw the advent of advertising technology – or AdTech. This is a term used to describe the tools and software used by advertisers to run, deliver, manage, and optimise advertising campaigns.</p><h2 id="how-has-adtech-evolved">How has AdTech evolved?</h2><p>The AdTech ecosystem comprises two major entities; the advertiser (demand-side) and the publisher (supply-side), and each has different goals; the former use AdTech to boost their campaign, zero in on their target market, and maximise their ROIs, while publishers use AdTech to optimise revenue generated from their ad inventory.</p><p>AdTech has evolved significantly since the debut of the first ad server in the late 1990s, and most platforms are now connected in some way to the programmatic advertising ecosystem – a series of technologies that allow ads to be bought and sold automatically.</p><p>One of these technologies is real-time bidding (RTB), which has been the source of much contention since it came to market in 2014. This technology has disrupted the media buying industry by introducing a far more efficient way to purchase advertising, bypassing media buyers, publishers, and ad networks.</p><p>RTB uses demand-side platforms (DSPs) to buy impressions among a marketplace of publisher sites, while targeting specific users. As an impression is loaded on a user’s web browser, information about that user and the page they’re on is passed to an ad exchange, which allows advertisers to bid in real-time for those impressions.</p><p>“It’s important to recognise that brands, agencies, and publishers are all benefiting from the rise of scaled contextual technology,” Tony Marlow, CMO at Integral Ad Science (IAS), tells <em>IT Pro</em>. “For advertisers, understanding context helps them build more impactful connections with their audiences by finding the optimal adjacencies for their campaign messaging. For publishers, smarter and more granular content classification means that they can package their inventory to be more relevant for both advertisers and consumers; this in turn unlocks extra yield.”</p><h2 id="why-is-rtb-the-source-of-such-controversy">Why is RTB the source of such controversy?</h2><p>Attitudes towards RTB and programmatic buying are becoming increasingly polarised. While, for advertisers, these technologies act as a convenient way to reach a target audience at scale and cost-effectively, for privacy campaigners, they act as a tool for the mass exploitation of user data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media" data-original-url="/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media">The future of AI in advertising and media</a></p></div></div><p>As laid out in a recent <a href="https://www.iccl.ie/wp-content/uploads/2022/05/Mass-data-breach-of-Europe-and-US-data-1.pdf" target="_blank">report by the Irish Council for Civil Liberties (ICCL)</a>, RTB relies on personal data – including a user’s location information, device details, and browsing habits – to personalise ads. On average, per day, a person’s data is shared 747 times in the US and 376 times in Europe, the ICCL report found. Combined, this comes to an average of 294 billion broadcasts per day in the US, 197 billion a day in Europe, and a staggering 178 trillion per year in the US and Europe combined.</p><p>These auctions generated over $117 billion in 2021 in the US and Europe, the report claims – and other estimates expect the RTB market to <a href="https://www.prnewswire.com/news-releases/real-time-bidding-market-to-grow-by-usd-16-52-bn--abb-ltd-and-adobe-inc-among-key-vendors--technavio-301458196.html" target="_blank">grow a further $16.52 billion</a> by 2026.</p><p>These statistics have caught the eye of regulators, too. The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> published a report in June 2019 <a href="https://www.itpro.com/policy-legislation/33889/ico-claims-adtech-industry-violating-data-protection-laws" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/33889/ico-claims-adtech-industry-violating-data-protection-laws">identifying a range of issues</a> in AdTech that amounted to critical <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection</a> violations.</p><p>It found the ​​multi-billion dollar industry, which is <a href="https://twitter.com/OCC_Strategy/status/809710412426002436" target="_blank">overwhelmingly dominated by Google and Facebook</a>, doesn’t gain consent from users when processing personal data, which includes information on sexuality, political leaning, and race. RTB was highlighted as the central tool through which personal data was being misused.</p><p>This represents a violation of standards set under the General Data Protection Regulation (GDPR), and the UK's <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act (DPA) 2018</a>, according to the report published by the UK data regulator.</p><p>"Under data protection law, using people's sensitive personal data to serve adverts requires their explicit consent, which is not happening right now," said the ICO's executive director for technology policy and innovation, Simon McDougall, at the time. "Sharing people's data with potentially hundreds of companies, without properly assessing and addressing the risk of these counterparties, raises questions around the security and retention of this data."</p><h2 id="why-is-the-ico-under-fire-over-rtb">Why is the ICO under fire over RTB?</h2><p>Since this report was published, the ICO says it’s been "encouraged" by steps the industry has taken, and has agreed on a range of new principles with the Interactive Advertising Bureau (IAB), a trade association for AdTech businesses. In that vein, the watchdog has yet to act or enforce any further regulation.</p><p>This led the Open Rights Group (ORG), a UK-based organisation that works to preserve digital rights and freedoms, to <a href="https://www.itpro.com/data-insights/data-processing/354573/ico-faces-legal-action-over-failure-to-regulate-adtech" target="_blank" data-original-url="https://www.itpro.com/data-insights/data-processing/354573/ico-faces-legal-action-over-failure-to-regulate-adtech">threaten legal action against the ICO</a> for taking “minimal steps” to enforce the law against the “massive data breaches” in the online ad industry.</p><p>"The ICO is a regulator, so it needs to enforce the law,” says the ORG’s executive director, Jim Killock. “It appears to be accepting that unlawful and dangerous sharing of personal data can continue, so long as 'improvements' are gradually made, with no actual date for compliance.”</p><p>Johnny Ryan, a senior fellow at the Irish Council for Civil Liberties and former Brave chief policy officer, went a step further and, in 2020, <a href="https://www.itpro.com/policy-legislation/data-protection/356423/ico-lambasted-for-falling-asleep-at-the-wheel" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/356423/ico-lambasted-for-falling-asleep-at-the-wheel">launched legal action</a> against Google, Facebook, Amazon, Twitter, and AT&T in Germany.</p><p>Under pressure from these different quarters, the ICO <a href="https://www.itpro.com/policy-legislation/information-commissioner/358402/ico-restarts-adtech-probe-following-threats-of" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/information-commissioner/358402/ico-restarts-adtech-probe-following-threats-of">restarted its probe in January 2021</a>. McDoughall said at the time it will also be reviewing the role of data brokers, which plays a large part in RTB, in the AdTech ecosystem.</p><h2 id="society-is-becoming-more-privacy-conscious">Society is becoming more privacy-conscious</h2><p>It’s not just digital rights advocates that have sounded the alarm about the AdTech industry, as consumers, too, are becoming more concerned about the trading of their personal information online.</p><p>Ossie Bayram, country director at the mobile AdTech firm Ogury, tells <em>IT Pro</em> that normal practices are crumbling under pressure from privacy-conscious users and regulators. People are becoming far more aware of the value of their own data, and they’re much more resistant to tracking. “As a consequence, traditional players, who continue to deliver ID-based and cookie-based campaigns, although representing a large proportion of the market, are bound to disappear in the coming years.”</p><p>Toby Evans, director of publisher and platform partnerships at SoPost, agrees, telling <em>IT Pro</em> that Facebook’s Cambridge Analytica scandal was a turning point in consumers’ attitudes towards online privacy. “What once seemed fairly harmless – and, to be fair, is still what keeps the worldwide web free to use – has increasingly become distinctly sinister around the edges,” he says.</p><p>“We’ve known for years that something is amiss: the Cambridge Analytica scandal of 2018 was a highly publicised case in which the mass of data mined from Facebook gave the company the ability to know more about Facebook users than they even knew about themselves. And when knowledge reaches that level, it can easily be used for manipulation – which is exactly what Cambridge Analytica did.”</p><h2 id="finding-a-way-out-of-the-adtech-warzone">Finding a way out of the AdTech warzone</h2><p>This widespread kickback has led some big-name tech companies to act. Apple, for example, introduced changes that allow iPhone users to choose which apps can track their behaviour across other apps, while <a href="https://www.itpro.com/security/privacy/354542/google-looks-to-replace-third-party-cookies-in-two-years" target="_blank" data-original-url="https://www.itpro.com/security/privacy/354542/google-looks-to-replace-third-party-cookies-in-two-years">Google will phase out third-party cookies</a> by 2023.</p><p>“Apple’s privacy changes and Google’s upcoming deprecation of third-party cookies have had a huge impact on the viability of many ad-targeting mechanisms – even if the more cynical of us may say that, given the scale of these businesses’ access to first-party data, their true aim is less altruistic and more akin to a power grab,” Evans adds. “But, in any case, hopefully we can soon all welcome a world in which a privacy-aware public can enjoy greater transparency and a fairer value exchange, the results of a kinder, fairer means of marketing.”</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=46975747&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/368388/what-is-social-mobile-analytics-and-cloud-smac" data-original-url="/business-strategy/digital-transformation/368388/what-is-social-mobile-analytics-and-cloud-smac">What is the social, mobile, analytics and cloud (SMAC) framework?</a></p></div></div><p>Many believe, as a result of these moves, the exploitation of cookies and advertising IDs will soon become obsolete. This would particularly apply with the creation of cookieless alternatives that’s seen AdTech platforms turn to contextual and semantic targeting.</p><p>“Companies with the right cultural mindsets often look for alternative solutions that achieve the same goal using a more privacy-friendly approach,” Dr Sachiko Scheuing, European privacy officer at Acxiom, tells <em>IT Pro</em>. “These companies are moving towards contextual advertising, online advertising using trusted third parties (having a company in between to anonymise the data), and advanced encryption techniques for a safer digital ecosystem.”</p><p>However, Scheuing believes that the ultimate solution is accountability from the AdTech companies themselves. “Consent is seen by many as the solution to AdTech regulation, but it is not a panacea for increased compliance,” she says. “The solution instead should be to have a stronger emphasis on accountability-based data protection, which can be furthered when AdTech companies think of the impact their products and services have on consumers’ right to data protection.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK gov invites experts to contribute to its overhauled AI regulatory approach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence-ai/368571/uk-gov-invites-experts-to-overhauled-ai-approach</link>
                                                                            <description>
                            <![CDATA[ The new approach will not adopt the EU's centralised model and sits alongside the National AI Strategy and Data Protection and Digital Information Bill ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aUdNp7g3EDopXpGiPWhVwA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kxZQEquVYmYZ83js5dGjm3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Jul 2022 10:21:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kxZQEquVYmYZ83js5dGjm3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of the Houses of Parliament by the Thames on a sunny day]]></media:description>                                                            <media:text><![CDATA[An image of the Houses of Parliament by the Thames on a sunny day]]></media:text>
                                <media:title type="plain"><![CDATA[An image of the Houses of Parliament by the Thames on a sunny day]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kxZQEquVYmYZ83js5dGjm3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government has announced its intention to introduce new regulations for artificial intelligence (AI) to plug ‘confusing’ gaps and inconsistencies in current regulatory approaches.</p><p>Industry experts, academics, and civil society organisations are invited to take part in a 10-week call for evidence that begins today and runs up until 26 September. The input will help shape the government’s actions in putting its plans into place.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai" data-original-url="/machine-learning/31708/what-are-the-pros-and-cons-of-ai">What are the pros and cons of AI?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/362082/building-an-ai-superpower-does-the-uk-stand-a-chance" data-original-url="/technology/artificial-intelligence-ai/362082/building-an-ai-superpower-does-the-uk-stand-a-chance">Building an AI superpower: Does the UK stand a chance?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/360974/uk-ten-year-plan-ai-superpower" data-original-url="/technology/artificial-intelligence-ai/360974/uk-ten-year-plan-ai-superpower">UK publishes ten-year plan to become an 'AI superpower'</a></p></div></div><p>Announcing the news this morning, the Department for Culture, Media and Sport (DCMS) said that it wants the regulations to differ from the <a href="https://www.itpro.com/policy-legislation/it-regulation/359986/gdpr-20-what-do-europes-new-ai-rules-mean-for-businesses" data-original-url="https://www.itpro.com/policy-legislation/it-regulation/359986/gdpr-20-what-do-europes-new-ai-rules-mean-for-businesses">EU’s centralised approach</a>.</p><p>It plans to introduce a set of rules that can be interpreted and enforced by numerous regulators such as the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a>, Ofcom, and the Competition and Markets Authority (CMA).</p><p>The government believes that by pursuing this decentralised model, each regulator will be able to take a “tailored approach” and apply the regulations more effectively in a range of different contexts. </p><p>While the final regulations have yet to be codified, the DCMS said the initial approach will require AI developers to adhere to six key principles:</p><ul><li>Ensure that AI is used safely</li><li>Ensure that AI is technically secure and functions as designed</li><li>Make sure that AI is appropriately transparent and explainable</li><li>Consider fairness</li><li>Identify a legal person to be responsible for AI</li><li>Clarify routes to redress or contestability</li></ul><p>The principles summarise the approach that was published in full this morning in the government’s latest <a href="https://www.gov.uk/government/publications/establishing-a-pro-innovation-approach-to-regulating-ai/establishing-a-pro-innovation-approach-to-regulating-ai-policy-statement">AI paper</a>. </p><p>According to the government’s research, organisations report a lack of clarity in the current regulations which is a particular issue for small businesses that may not have access to the legal support required to interpret them accurately.</p><p>The new regulations will also aim to tackle the perceived inconsistencies with enforcement. Different regulators are currently seen as having varying levels of power to regulate AI within their respective remits, which means AI products could subsequently reach the market with different levels of oversight depending on the target market.</p><p>The government also acknowledges that current legislation has not been developed with consideration to AI. This means the associated risks with the technology aren’t properly addressed and developers <a href="https://www.itpro.com/technology/artificial-intelligence-ai/361871/most-uk-businesses-say-data-regulations-stifle-ai" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/361871/most-uk-businesses-say-data-regulations-stifle-ai">may not be able to innovate in the most optimal regulatory conditions</a>.</p><p>The new rules will aim to foster innovation in the AI sector, ensuring the UK continues to grow and compete as a global innovator in the space, while also addressing the widespread issues with the technology such as <a href="https://www.itpro.com/business/business-strategy/356036/tech-firms-are-saving-face-by-dropping-facial-recognition" data-original-url="https://www.itpro.com/business/business-strategy/356036/tech-firms-are-saving-face-by-dropping-facial-recognition">reliability</a> and <a href="https://www.itpro.com/technology/artificial-intelligence-ai/361824/how-biased-is-your-app" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/361824/how-biased-is-your-app">unfair biases</a>.</p><p>Regulators will be encouraged to consider “lighter touch options” such as offering guidance or creating trial environments so products can be tested before reaching the market.</p><p>The DCMS said the UK leads Europe and currently sits third in the world for private AI investment. Domestic companies attracted £3.88 billion in investment last year, it said.</p><p>“We want to make sure the UK has the right rules to empower businesses and protect people as AI and the use of data keeps changing the ways we live and work,” said Damian Collins, digital minister. </p><p>“It is vital that our rules offer clarity to businesses, confidence to investors and boost public trust. Our flexible approach will help us shape the future of AI and cement our global position as a science and tech superpower.”</p><h2 id="data-reform-bill-tie-in">Data Reform Bill tie-in</h2><p>The <a href="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr">Data Reform Bill</a>, recently renamed to the Data Protection and Digital Information Bill, is closely linked to the proposed overhaul of the UK’s <a href="https://www.itpro.com/technology/artificial-intelligence-ai/367275/the-it-pro-podcast-do-we-need-ai-regulation" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/367275/the-it-pro-podcast-do-we-need-ai-regulation">AI regulations</a>.</p><p>The bill is currently going through parliament and aims to offer greater flexibility to the way businesses can use data. The rules will dilute those introduced by the GDPR and domestically by the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act 2018</a> but falls short of abolishing it entirely.</p><p>Announcing the Bill last month, the government said it would bring around £1 billion in savings for businesses while eliminating the ‘unnecessary’ red tape and box-ticking exercises that the GDPR’s rules enforce.</p><p>Although the new Bill aims to water down the data protections afforded by the GDPR, the government insists it will continue to preserve the privacy of individuals but do so in a way that allows businesses to use personal data more easily for things like <a href="https://www.itpro.com/business/policy-legislation/368393/government-to-boost-ai-data-mining-research-copyright-law-change" data-original-url="https://www.itpro.com/business/policy-legislation/368393/government-to-boost-ai-data-mining-research-copyright-law-change">scientific research</a>.</p><h2 id="national-ai-strategy">National AI Strategy</h2><p>The new approach to regulating AI is the latest step in the government's <a href="https://www.itpro.com/technology/artificial-intelligence-ai/360974/uk-ten-year-plan-ai-superpower" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/360974/uk-ten-year-plan-ai-superpower">National AI Strategy</a>. Initially announced last year, the ten-year strategy aims to keep the UK in its <a href="https://www.itpro.com/technology/artificial-intelligence-ai/362082/building-an-ai-superpower-does-the-uk-stand-a-chance" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/362082/building-an-ai-superpower-does-the-uk-stand-a-chance">leading position as a global AI innovator</a>.</p><p>Effective governance of the technology formed one of the key pillars of the strategy, along with ensuring the technology benefits all areas of the economy. </p><p>As part of the strategy, the government also plans to build a National AI Research and Innovation Programme that will provide a platform for collaboration among all the country's leading AI experts and researchers, to boost public sector adoption of AI.</p><p>Separate programmes are also being proposed to accelerate the development of AI outside of London and the South East of England.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why does the UK government want to replace GDPR with the Data Reform Bill? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill</link>
                                                                            <description>
                            <![CDATA[ Critics brand the EU's regulations as inflexible and counterproductive, but do the claims stand up to scrutiny? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gCGTswQiektQP9kcVPnwqf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DxxHWKpW6jiBgkQBp2gbpM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Jul 2022 07:00:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/QST9gbWQZLs5T4KfoM2StL.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DxxHWKpW6jiBgkQBp2gbpM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The UK in red and the EU in blue as seen in a digitised map]]></media:description>                                                            <media:text><![CDATA[The UK in red and the EU in blue as seen in a digitised map]]></media:text>
                                <media:title type="plain"><![CDATA[The UK in red and the EU in blue as seen in a digitised map]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DxxHWKpW6jiBgkQBp2gbpM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>On leaving the European Union (EU), the UK government integrated core pieces of legislation, including the General Data Protection Regulation (GDPR), into British law. Significant changes to the data protection regime, however, are on the cards, with the newly announced <a href="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr">Data Reform Bill</a> set to begin its journey through parliament as the government sets its sights on replacing GDPR.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr" data-original-url="/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr">UK unveils Data Reform Bill, scrapping parts of GDPR and promising £1 billion in savings</a></p></div></div><p>This cements the government’s long standing intent to move away from the EU’s data protection regime, now the UK has left the EU. Instead, the UK will embrace a framework which Downing Street says will ‘promote innovation’ and slash the reams of <a href="https://www.itpro.com/business-strategy/digital-transformation/360082/cutting-through-the-red-tape-of-government-it" target="_blank" data-original-url="https://www.itpro.com/business-strategy/digital-transformation/360082/cutting-through-the-red-tape-of-government-it">red tape</a> often associated with implementing the regulations. </p><p>Do claims around GDPR being too overbearing, inflexible and discouraging to research stand up to scrutiny, though? If the government’s to be believed, the Data Reform Bill will usher in a new age of data-powered innovation, with regulatory costs and bureaucracy involved with <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready" target="_blank" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready">GDPR compliance</a> slashed for businesses up and down the country.</p><h2 id="the-data-reform-bill-might-mitigate-risk-aversion">The Data Reform Bill might mitigate risk aversion</h2><p>“The Data Reform Bill demonstrates that the UK government recognises the power of the data in the digital economy, for which an appropriately clear and effective regulatory regime is required to enable innovation for new technologies,” Gita Shivarattan, UK head of data protection law services at Ernst & Young, tells <em>IT Pro</em>.</p><p>Shivarattan continues: “At present, there is a view that the current GDPR legislation has created a culture of ‘risk aversion’ within businesses due to uncertainty around enforcement risk, leading to an overly cautious approach to leveraging personal data (whether through <a href="https://www.itpro.com/business-strategy/data-insights/359060/why-diy-data-collection-should-come-before-automation" target="_blank" data-original-url="https://www.itpro.com/business-strategy/data-insights/359060/why-diy-data-collection-should-come-before-automation">data collection</a> or reuse) where they might legally be able to, such as in research and development (R&D).”</p><p>How data flows across borders is protected as a component of GDPR, but the EU has been slow to sign data transfer agreements with states across central Europe. This has led to most businesses erring on the side of caution and applying GDPR with little flexibility. In turn, it often led to issues in terms of commercial data exchange between large and small enterprises, impeding their growth and abilities to deliver digital services to their customers.</p><p>The government’s plans with regards to GDPR also coincide with its newly announced <a href="https://www.itpro.com/server-storage/high-performance-computing-hpc/368276/uk-gov-to-launch-ten-year-compute-review" target="_blank" data-original-url="https://www.itpro.com/server-storage/high-performance-computing-hpc/368276/uk-gov-to-launch-ten-year-compute-review">digital strategy</a>, which aims to set the UK on the path to becoming a global tech superpower. Taken hand-in-hand, the government seems adamant on redrawing the digital legislative fabric that powers UK businesses, erring more towards deregulation and cutting bureaucracy that the EU, for many, embodied. This appetite for change notwithstanding, the government must also reckon with the inevitable friction with the EU that such moves will cause. </p><h2 id="ditching-gdpr-might-risk-data-adequacy">Ditching GDPR might risk data adequacy</h2><p>The risk with the forthcoming Data Reform Bill is it’ll water down standards too far. The challenge for the Department for Digital, Culture, Media and Sport (DCMS) is devising reforms that maintain the high standards in <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">safeguarding personal data,</a> yet imbues confidence in businesses to use data to innovate. There’s also the question of whether any reforms could jeopardise the UK’s current <a href="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu">data adequacy status with the EU</a>; the last thing businesses want is a halt to the flow of data across borders. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/368115/ai-is-now-powerful-enough-to-automate-the-back-office" data-original-url="/business-strategy/automation/368115/ai-is-now-powerful-enough-to-automate-the-back-office">AI is now powerful enough to automate the back office</a></p></div></div><p>Can the stated drive to enhance the development of artificial intelligence (AI), the UK's general compute capability, and the need to protect digital privacy ever be satisfactorily reconciled into legislation that drives business and supports privacy for everyone's personal data? Amending, or removing, Article 22 of GDPR could be problematic for the UK’s data adequacy, for example, as it considers how data and <a href="https://www.itpro.com/business-strategy/automation/368115/ai-is-now-powerful-enough-to-automate-the-back-office" target="_blank" data-original-url="https://www.itpro.com/business-strategy/automation/368115/ai-is-now-powerful-enough-to-automate-the-back-office">automated systems</a> should operate together to protect data privacy. The UK’s proposed reforms would lift the prohibition on ‘soley’ automated decision making, and instead clarify a right to specific safeguards where AI-powered systems are used without human oversight. </p><p>With the UK’s data adequacy status expiring in 2025, any significant divergence from Article 22 may mean, by the time the time for renewal comes along, the EU feels the UK has moved too far away from the track and more towards an Americanised view on data protection and data-powered innovation. </p><p>Speaking to <em>IT Pro</em>, Elizabeth Schweyen, senior manager of global privacy and compliance at Druva, wonders what a future data exchange between the UK and EU could look like: "It will be interesting to see the long-term implications in the event the UK is no longer seen as ‘adequate’ by the EU, thus gaining restrictions with the flow of data between the EU-UK that aren’t currently there.”</p><h2 id="gdpr-is-already-at-risk-of-becoming-out-of-date">GDPR is already at risk of becoming out-of-date</h2><p>The incoming Information Commissioner John Edwards has the task of realising much of the government's plans to overhaul the regulations that govern digital services and how data is collected, stored, manipulated, and exchanged.</p><p>“GDPR is often cited as the strongest and most comprehensive data protection law in the world and in history, yet four years on there are still massive question marks over how successful it’s been,” James Walker, CEO of Rightly, consumer data action service, tells <em>IT Pro</em>. </p><p>“We’re still seeing businesses exploiting loopholes in GDPR,” Walker continues, “and when companies are found to be in breach of these laws, the industry regulator – the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> – has been largely toothless in taking any action.”</p><p>Nevertheless, the government has instead taken issue with the perceived overbearing nature of the ICO in its approach to enforcement action, which has fuelled major organisational reforms. Ministers will also have oversight over the statutory codes the ICO devises to enforce policies across the industry.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other" data-original-url="/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other">GDPR and Brexit: How will one affect the other?</a></p></div></div><p>Since GDPR came into force, at times it’s felt as if the EU’s rules were in danger of becoming antiquated. Those officiating GDPR have also had to contend with a rapidly changing technology space. AI, the <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot" target="_blank" data-original-url="https://www.itpro.com/cloud-computing/28037/what-is-iot">Internet of Things (IoT)</a>, <a href="https://www.itpro.com/mobile/28081/what-is-5g" target="_blank" data-original-url="https://www.itpro.com/mobile/28081/what-is-5g">5G</a> uptake and <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing" target="_blank" data-original-url="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a> are all expanding. </p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=46975747&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>It's too early to assess whether the reforms will achieve what the government has set out to do, largely because its diagnosis of GDPR may not hold up. Nevertheless, should the reforms work, UK businesses could find themselves enjoying a landscape in which costs will come down and there’ll be fewer hoops to jump through, all while the same standard of data protection is maintained.</p><p>As Druva’s Elizabeth Schweyen concludes, reform of regulations needs to tread carefully: “Given the pace that technology is advancing, it doesn’t hurt to take a look at GDPR to understand the areas that may not have been considered when the law was passed in 2016 and add in provisions to protect and account for emerging technologies. However, I do not think the time is right to loosen data protection requirements.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MvhpzpHefE4nmX4AeKi7si" name="MvhpzpHefE4nmX4AeKi7si.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/MvhpzpHefE4nmX4AeKi7si.png" mos="https://cdn.mos.cms.futurecdn.net/MvhpzpHefE4nmX4AeKi7si.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Deliver a modernised end-user experience that pays for itself</strong></p><p class="fancy-box__body-text">Start modernising PC lifecycle management today</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/367723/deliver-a-modernised-end-user-experience-that-pays" data-original-url="/business-strategy/digital-transformation/367723/deliver-a-modernised-end-user-experience-that-pays">FREE DOWNLOAD</a></p></div></div><p>The flexibility the government refers to when discussing GDPR reforms has yet to be fully defined. Indeed, some aspects of GDPR in its current form could be described as restrictive to business innovation. Any reforms must tread carefully to ensure consumer confidence is maintained in how the data they provide is a fair exchange for the products or services they want to buy or access. </p><p>The UK wants to reform its data protection regime post-Brexit, but it still needs to maintain a relationship – and data adequacy – with the EU. Businesses will hope that any new measures introduced with the Data Reform Bill will pose a net benefit, and refrain from setting the UK on a direct collision course with EU lawmakers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK unveils Data Reform Bill, scrapping parts of GDPR and promising £1 billion in savings ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/368309/uk-data-reform-bill-waters-down-gdpr</link>
                                                                            <description>
                            <![CDATA[ The reforms, which stop short of abolishing GDPR entirely, also include an overhaul to the Information Commissioner's Office and a watering-down of rules around consent for scientific research ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">81cdnfqu8m98Kz1BfydNWC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hb5VaFP3oFPPJF2jKYmjs7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jun 2022 21:30:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hb5VaFP3oFPPJF2jKYmjs7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up photo of Secretary of State for Digital, Culture, Media and Sport Nadine Dorries, as she walks outside Number 10 Downing Street]]></media:description>                                                            <media:text><![CDATA[A close up photo of Secretary of State for Digital, Culture, Media and Sport Nadine Dorries, as she walks outside Number 10 Downing Street]]></media:text>
                                <media:title type="plain"><![CDATA[A close up photo of Secretary of State for Digital, Culture, Media and Sport Nadine Dorries, as she walks outside Number 10 Downing Street]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hb5VaFP3oFPPJF2jKYmjs7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government has unveiled the details behind its widely anticipated proposals to replace the General Data Protection Regulation (GDPR) with more flexible and less stringent data protection laws.</p><p>The EU’s “highly complex” GDPR, which came into force four years ago, has held back businesses from using data “as dynamically as they could”, according to the Department for Digital, Culture, Media and Sport (DCMS).</p><p>The Data Reform Bill will scrap what the government decries as “red tape and pointless paperwork”, while lowering the barrier for personal data to be used in scientific research. As part of this package, the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> will also be restructured.</p><p>“Today is an important step in cementing post-Brexit Britain’s position as a science and tech superpower,” DCMS secretary Nadine Dorries said. “Our new Data Reform Bill will make it easier for businesses and researchers to unlock the power of data to grow the economy and improve society, but retains our global gold standard for data protection.”</p><p>“Outside of the EU we can ensure people can control their personal data, while preventing businesses, researchers and civil society from being held back by a lack of clarity and cumbersome EU legislation.”</p><h2 id="death-to-the-box-ticking-gdpr">Death to the “box-ticking” GDPR </h2><p>The UK government has long argued that a lack of clarity in GDPR meant seeking consent from individuals turned into a box-ticking exercise, with the current regime putting a disproportionate burden on small businesses.</p><p>The government has hinted the Data Reform Bill will ditch the need for organisations to seek explicit consent before processing personal data on every occasion, although it hasn’t outlined what this will look like in practice. It says, however, the new data protection rules will be focused on outcomes rather than going by the letter of the law.</p><p>Under this laissez-faire approach, some businesses won’t need to appoint a <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30326/what-is-a-data-protection-officer" target="_blank" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/30326/what-is-a-data-protection-officer">data protection officer (DPO)</a> and won’t need to conduct data protection impact assessments (DPIA) when developing new tools or services.</p><p>The example DCMS uses is that of an independent pharmacist no longer needing to recruit a dedicated DPO, provided they can effectively manage risks themselves.</p><p>Organisations, though, will still need to have a privacy management programme in place to ensure they’re accountable for how they process personal data.</p><p>Scrapping these administrative elements of GDPR will save businesses approximately £1 billion, the government claims.</p><h2 id="retooling-the-ico">Retooling the ICO</h2><p>Under the proposals, the UK data regulator will be reorganised to have a chair, chief executive, and a board in order to introduce a wider set of skills to support decision-making. The government also wants to broaden the responsibilities underpinning the ICO’s work, with everything currently sitting on the shoulders of the Information Commissioner.</p><p>“I share and support the ambition of these reforms,” said the <a href="https://www.itpro.com/policy-legislation/information-commissioner/360352/new-zealand-privacy-commissioner-tipped-for-uks" data-original-url="https://www.itpro.com/policy-legislation/information-commissioner/360352/new-zealand-privacy-commissioner-tipped-for-uks">recently appointed</a> Information Commissioner, John Edwards. “I am pleased to see the government has taken our concerns about independence on board.</p><p>“Data protection law needs to give people confidence to share their information to use the products and services that power our economy and society. The proposed changes will ensure my office can continue to operate as a trusted, fair and impartial regulator, and enable us to be more flexible and target our action in response to the greatest harms.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">DCMS lifts the lid on UK GDPR reforms, including ICO restructure <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" data-original-url="/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">The risks and strategies of using privacy as a business differentiator</a> General Data Protection Regulation (GDPR)</p></div></div><p>The ICO will also be given new, “clearer” objectives, to be set out in legislation, which will give the regulatory more focus. They’ll also require the regulator to consider factors like economic growth, innovation and competition when making judgements, rather than going by the letter of the law.</p><p>Political oversight will also be added to the way the ICO develops statutory codes, which it routinely publishes to outline best practice for organisations using data in specific ways – such as protecting children’s data online.</p><p>The secretary of state must personally approve each piece of statutory guidance in future before they’re presented to Parliament.</p><h2 id="lowering-the-barrier-for-data-processing">Lowering the barrier for data processing</h2><p>Among the most significant elements of the package is watering down the legal requirements for institutions and companies to process personal data for research purposes.</p><p>The Data Reform Bill will more clearly define the scope of scientific research, and will give scientists clarity about when they can – and when they don’t need to – obtain user consent to collect or use data for broad research purposes.</p><p>Under the current regime, users need to give their explicit consent for data to be processed for a specified reason. The data collected cannot then be used, without re-acquiring consent, if the purpose of the research changes. Now, researchers only need to specify they’re using data in, for example, cancer research generally as opposed to a particular cancer study.</p><p>The UK government has long considered abolishing GDPR and replacing it with a new set of data protection laws that are more flexible, and reduce the administrative and legal burden placed on businesses.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="s7hnF2HF5HjCJogZeSiun4" name="s7hnF2HF5HjCJogZeSiun4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/s7hnF2HF5HjCJogZeSiun4.png" mos="https://cdn.mos.cms.futurecdn.net/s7hnF2HF5HjCJogZeSiun4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Understanding the economics of in-cloud data protection</strong></p><p class="fancy-box__body-text">Data protection solutions designed with cost optimisation in mind</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/367728/understanding-the-economics-of-in-cloud-data-protection" data-original-url="/cloud/cloud-computing/367728/understanding-the-economics-of-in-cloud-data-protection">FREE DOWNLOAD</a></p></div></div><p>Last June, the prime minister Boris Johnson <a href="https://www.itpro.com/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules">welcomed an agenda</a> that included scrapping consent altogether, and removing human oversight from artificial intelligence (AI) tools and systems. DCMS announced a consultation on a set of less extreme proposals in September last year, which has culminated in the package of measures it’s announced tonight.</p><p>Edwards, who was appointed Information Commissioner on 4 January, <a href="https://www.itpro.com/policy-legislation/information-commissioner/367179/ico-chief-warns-ministers-against-ditching-gdpr" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/information-commissioner/367179/ico-chief-warns-ministers-against-ditching-gdpr">previously warned ministers against scrapping the safeguards</a> GDPR gives data subjects. That the Data Reform Bill has won his backing suggests he's satisfied the new regime will maintain high standards of data protection.</p><h2 id="34-irresponsible-34-reforms">"Irresponsible" reforms</h2><p>How the data reforms will affect the UK's relationship with the EU remains unclear. The UK was able to <a href="https://www.itpro.com/policy-legislation/data-protection/358674/eu-grants-the-uk-provisional-data-adequacy-status" data-original-url="https://www.itpro.com/policy-legislation/data-protection/358674/eu-grants-the-uk-provisional-data-adequacy-status">secure a data adequacy agreement</a> with the EU following Brexit, which allowed data to flow from the EU to the UK unhindered, however that agreement is contingent on the EU continuing to recognise the UK as having data protections as robust as that of the European Union. Many industry experts have warned that attempts to deviate too far from GDPR could put this agreement at risk, causing severe disruption for businsesses across Europe.</p><p>Peter Church, Counsel at multinational law firm Linklaters, highlighted that a number of more radical suggestions have been removed from the final proposals, including the possibility of replacing GDPR entirely in favour of a brand new framework.</p><p>"This is hardly a surprise given data protection laws are now a global norm and the GDPR is the template upon which many of those laws are based," said Church. "This is good news for data flows between the EU and the UK, as these more modest reforms mean the EU Commission is less likely to revoke the UK’s adequacy finding, which would have caused significant disruption."</p><p>However, Mariano delli Santi, data protection campaigner at Open Rights Group, called the proposals "irresponsible", adding that "they risk leading to a massive and expensive rupture with the EU, making data transfers costly for UK businesses, costing jobs during an economic downturn".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Using Google Takeout to reclaim your data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/368243/using-google-takeout-to-reclaim-your-data</link>
                                                                            <description>
                            <![CDATA[ Everyone knows your data drives the Google machine, but now you can find out exactly what it holds on you ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8KeBLf9JRQsaweesRDGkua</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jsQoshWtfv7teYLS92r6jj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 11 Jun 2022 07:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jsQoshWtfv7teYLS92r6jj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several anonymous faces imposed with binary to represent privacy]]></media:description>                                                            <media:text><![CDATA[Several anonymous faces imposed with binary to represent privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Several anonymous faces imposed with binary to represent privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jsQoshWtfv7teYLS92r6jj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Do you use Google products and services? Given there are just shy of two billion Google accounts, the chances are pretty high that you do. Everyone knows that what drives the Google machine is data; your data. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" data-original-url="/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">The risks and strategies of using privacy as a business differentiator</a></p></div></div><p>I’ve written a lot over the years about ways to strengthen your Google security posture and how to lock down your privacy as far as you can while reaping the benefits of Google Workspace (foremerly <a href="https://www.itpro.com/google-docs/33273/google-g-suite-review-suite-like-chocolate" target="_blank" data-original-url="https://www.itpro.com/google-docs/33273/google-g-suite-review-suite-like-chocolate">G Suite</a>). I’m not here to repeat myself, but instead shed light on how to find out what Google knows about you. </p><p>Well, more precisely, how to download the data Google holds from your use of services such as Gmail, Calendar, Maps, Pay, among countless others. </p><h2 id="what-is-google-takeout">What is Google Takeout?</h2><p>Google Takeout is a data visibility tool developed by in-house engineers collectively named, and I kid you not, the Google Data Liberation Front. It has a multitude of use cases, including making an archive of your contacts and images for example, but also discovering just what personal data Google holds under your account umbrella. </p><p>You’ll need to sign into your Google account if you haven't already, and then head to the <a href="http://takeout.google.com" target="_blank">Google Takeout site</a> to get started. Here you’ll be met with a list of Google products from which you can select the specific data you wish to download. In my case, this meant a staggering 50 product categories to choose from. Your mileage will vary, as will just how much data you will end up downloading. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oKfU7fJbHo2gH4LDuzQLtd" name="" alt="The first step of the Google Takeout procedure" src="https://cdn.mos.cms.futurecdn.net/oKfU7fJbHo2gH4LDuzQLtd.jpg" mos="https://cdn.mos.cms.futurecdn.net/oKfU7fJbHo2gH4LDuzQLtd.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>If you’ve been paying attention and following some of my <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">privacy tips</a> across the years then chances are you’ve already set expiration dates on certain data sets, but even so, be prepared for a large ZIP file. Also, be prepared for a wait before you can download it. Google itself warns this can take “possibly hours or days” to complete; you’ll get a link by email once the report is ready. </p><p>This is where tailoring the archive export to your own needs comes in useful. By way of an example that can hugely reduce both download size and report preparation time, you might want to exclude the self-explanatory “access log activity”. If you’re curious, you can customise the download by filtering either by activity (a list of Google services accessed by your devices, such as your phone syncing with Gmail), or devices that have accessed your account over the collection period. </p><h2 id="what-data-can-you-reclaim-from-google">What data can you reclaim from Google?</h2><p>Just by browsing through the list itself you’ll likely be shocked, or perhaps just have your thoughts on data collection validated. I hope you’re sitting down as the list includes: </p><ul><li><strong>Android Device Configuration Service</strong>: Device attributes, account identifiers, etc</li><li><strong>Blogger</strong>: Blogs, posts, comments, settings</li><li><strong>Calendar</strong>: Data</li><li><strong>Chrome</strong>: Bookmarks, autofill data, extensions, browser history, etc</li><li><strong>Cloud Print</strong>: History</li><li><strong>Contacts</strong></li><li><strong>Data Shared for Research</strong></li><li><strong>Drive</strong>: All your files</li><li><strong>Fit</strong>: Workout data, sleep data, daily metrics, etc</li><li><strong>Gmail</strong>: Messages and attachments</li><li><strong>Google Account</strong>: Activity</li><li><strong>Google Cloud Search</strong>: Content metadata ingested as part of the indexing flow</li><li><strong>Google Pay</strong>: Activity, transaction history, etc</li><li><strong>Google Store</strong>: Purchases, subscriptions, reviews</li><li><strong>Hangouts</strong>: Conversation history and attachments</li><li><strong>Home</strong>: Device and history data</li><li><strong>Keep</strong>: Notes and attachments</li><li><strong>Location</strong>: History data</li><li><strong>Maps</strong>: Preferences and personal places</li><li><strong>My Activity</strong>: Activity data with images and audio attachments</li><li><strong>News</strong>: Publications, categories and source data</li><li><strong>Photos and videos</strong></li><li><strong>Play Store</strong>: App installs, ratings</li><li><strong>Shopping</strong>: Order history, addresses, reviews, loyalty</li><li><strong>Reminders</strong>: History</li><li><strong>Search</strong>: Ratings, reviews and ‘other contributions’</li><li><strong>Tasks</strong>: Open and completed task data</li><li><strong>YouTube/YouTube Music:</strong> Watch and search history, videos, comments and content created</li></ul><p>I didn’t even include everything that I could choose from within that epic list.</p><h2 id="how-to-export-your-google-data">How to export your Google data</h2><p>Once you’ve chosen the data you want to export, you click a couple of buttons and then wait for that email. Be warned, your ZIP file could be a few GBs in size depending on what you’ve selected and how much data Google has a hold of. Also note that videos and images bump sizes up considerably.</p><p>It's worth mentioning, at this point, that you might be restricted by your organisation's internal Google Workspace policies, as far as exporting your personal data is concerned. If that's the case, you'll need to have a conversation with your IT adminstrators. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="N2uF3rGbyrJeFhbHkH5tn6" name="" alt="The second step of the Google Takeout procedure" src="https://cdn.mos.cms.futurecdn.net/N2uF3rGbyrJeFhbHkH5tn6.jpg" mos="https://cdn.mos.cms.futurecdn.net/N2uF3rGbyrJeFhbHkH5tn6.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31330/how-to-reclaim-your-data-from-google-facebook" data-original-url="/general-data-protection-regulation-gdpr/31330/how-to-reclaim-your-data-from-google-facebook">How to reclaim your data from Google, Facebook, Microsoft, Apple under GDPR</a></p></div></div><p>Unzip the archive and you’ll have folders for each category which contain a combination of .json, .mbox, .html and .csv files. If you want to delete at least some of this data without deleting your Google Account or a particular service, head to the <a href="http://myactivity.google.com">My Activity page</a> where you can do so for web and app activity, location history and YouTube history. </p><p>Services you no longer have any use for can be deleted from the Data & Privacy section of your Google account, where you can also delete the account itself along with all data if you’re going for the nuclear option. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Clearview AI fined £7.5m over improper use of UK data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/information-commissioner/367759/ico-hands-out-ps75m-fine-for-clearview-ai</link>
                                                                            <description>
                            <![CDATA[ Australian facial recognition firm collected 20 billion images from the internet without consent in order to build its database ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jvYPFgULarUAS9wSSXnScc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b89MxTwXvovmNbWpwoL4KD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 May 2022 10:20:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b89MxTwXvovmNbWpwoL4KD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A finger about to press the Clearview AI App on a device]]></media:description>                                                            <media:text><![CDATA[A finger about to press the Clearview AI App on a device]]></media:text>
                                <media:title type="plain"><![CDATA[A finger about to press the Clearview AI App on a device]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b89MxTwXvovmNbWpwoL4KD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's Information Commissioner (ICO) has fined Clearview AI £7.5 million for using images of British people in its systems, which were collected from the web and social media. </p><p>The controversial Australian firm supplies facial recognition technology to law enforcement agencies around the world and its systems have caused concern as it uses data scraped from publicly available online sources.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/367222/clearview-ai-version-20-facial-recognition" data-original-url="/technology/artificial-intelligence-ai/367222/clearview-ai-version-20-facial-recognition">Clearview AI unveils version 2.0 of its facial recognition software</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/information-commissioner/361694/clearview-ai-ico-fine-violate-data-protection-laws" data-original-url="/policy-legislation/information-commissioner/361694/clearview-ai-ico-fine-violate-data-protection-laws">Clearview AI faces £17 million fine for violating UK data protection laws</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/biometrics/366970/ukraine-access-to-clearview-ai-facial-recognition-tech" data-original-url="/security/biometrics/366970/ukraine-access-to-clearview-ai-facial-recognition-tech">Ukraine given access to Clearview AI's controversial facial recognition tech</a></p></div></div><p>A <a href="https://www.itpro.com/policy-legislation/information-commissioner/361694/clearview-ai-ico-fine-violate-data-protection-laws" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/information-commissioner/361694/clearview-ai-ico-fine-violate-data-protection-laws">joint investigation between the UK's data regulator and the Office of the Australian Information Commissioner</a> (OAIC) found that Clearview had collected more than 20 billion images from the internet, mostly social media, to create its online database. However, it failed to inform people that their images were being collected or used for this purpose.</p><p>The ICO also found that Clearview had breached UK data protection laws by failing to have a lawful reason for collecting the information and for not having a process to stop the data from being "retained indefinitely".</p><p>The penalty also came with an enforcement notice ordering Clearview to stop <a href="https://www.itpro.com/security/biometrics/356396/uk-and-australian-data-regulators-to-investigate-clearview-ai" target="_blank" data-original-url="https://www.itpro.com/security/biometrics/356396/uk-and-australian-data-regulators-to-investigate-clearview-ai">obtaining and using the personal data of UK residents</a>. The company no longer offers its services in the UK, though information for UK residents was still being used in systems sold in other countries, according to the ICO.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NJSDBJZzAjpg5aq4yVq3A8" name="NJSDBJZzAjpg5aq4yVq3A8.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8.png" mos="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Recommendations for managing AI risks</strong></p><p class="fancy-box__body-text">Integrate your external AI tool findings into your broader security programs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/367499/recommendations-for-managing-ai-risks" data-original-url="/technology/artificial-intelligence-ai/367499/recommendations-for-managing-ai-risks">FREE DOWNLOAD</a></p></div></div><p>"The company not only enables identification of those people but effectively monitors their behaviour and offers it as a commercial service," John Edwards, the Information Commissioner said. "That is unacceptable. That is why we have acted to protect people in the UK by both fining the company and issuing an enforcement notice."</p><p>Clearview became notorious in 2019 when reports surfaced that it was ordered to <a href="https://www.itpro.com/policy-legislation/data-governance/354628/twitter-demands-clearview-ai-stops-using-its-images-to" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-governance/354628/twitter-demands-clearview-ai-stops-using-its-images-to">cease and desist scraping data from Facebook and Twitter by the companies themselves</a>. The firm is popular with law enforcement, particularly in the US, where its app is used to match uploaded images to its database. Matched images will provide details on the subject and links to where the image was from, such as a social media page.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The cookie phase-out might precede an AdTech apocalypse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/marketing-comms/digital-marketing/367745/third-party-cookie-phase-out-adtech-apocalypse</link>
                                                                            <description>
                            <![CDATA[ With the industry phasing out third-party cookies, what does this mean for businesses reliant on them to track and improve their campaigns? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iRv4YmxM7NQy4T5g6g9o1P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Yba8iGL9AZQMiyEFkeecrR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 May 2022 07:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/QST9gbWQZLs5T4KfoM2StL.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Yba8iGL9AZQMiyEFkeecrR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A mouse cursor hovering over an &amp;#039;Accept Cookies&amp;#039; button]]></media:description>                                                            <media:text><![CDATA[A mouse cursor hovering over an &amp;#039;Accept Cookies&amp;#039; button]]></media:text>
                                <media:title type="plain"><![CDATA[A mouse cursor hovering over an &amp;#039;Accept Cookies&amp;#039; button]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Yba8iGL9AZQMiyEFkeecrR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The announcement that Chrome would stop supporting third-party cookies sent shock waves across the digital marketing community, especially those who’ve relied upon this data to target their messages at defined audiences. </p><p>Google has already announced it intends to begin the rollout of the <a href="https://www.itpro.com/network-internet/34261/google-web-initiative-aims-to-walk-the-line-between-privacy-and-advertising" target="_blank" data-original-url="https://www.itpro.com/network-internet/34261/google-web-initiative-aims-to-walk-the-line-between-privacy-and-advertising">Privacy Sandbox Initiative</a> to developers in late 2022, with the phase-out of third-party <a href="https://www.itpro.com/security/361576/what-are-cookies" target="_blank" data-original-url="https://www.itpro.com/security/361576/what-are-cookies">cookies</a> pencilled in for the end of next year. Essentially, the move would see individual data points from users grouped into what Google calls 'cohorts,’ which marketers would use to target their messages. This attempts to shift the emphasis away from profiling individual users using third-party cookies, in favour of tapping into the swelling public opinion around <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">digital privacy</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/361576/what-are-cookies" data-original-url="/security/361576/what-are-cookies">What are cookies</a></p></div></div><p>Google’s proposals haven’t come without controversy, however, with the Competition and Markets Authority (CMA) intervening earlier this year and extracting a set of commitments from the tech giant. The regulator was particularly concerned about user <a href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">privacy</a> as well as the impact the Privacy Sandbox could have on publishers and the wider digital advertising market. </p><p>Indeed, Google has a stranglehold over the industry, with Chrome holding 64% of the browser market, according to <a href="https://gs.statcounter.com/browser-market-share" target="_blank">Statcounter</a>. Any significant changes made to the platform, therefore, will affect swathes of consumers and businesses alike. Given the direction of travel as the cookie phase-out continues, marketers must become far more creative and attentive to user privacy and personal data.</p><h2 id="cookies-might-be-doing-more-harm-than-good">Cookies might be doing more harm than good</h2><p>The frustration users feel, especially when accessing commercial online services, is often a lack of control over the personal data they must relinquish to buy into something or access a service. GDPR was supposed to give power back to users, who are now asked for their explicit permission before their information can be used. There's also a level of transparency, but intrusive third-party cookies, which track users’ digital footprints, remain an active part of the ecosystem.</p><p>Neel Pandya, CEO of Europe and APAC, Pixis, succinctly tells <em>IT Pro</em>: "The demise of cookies does not mean the demise of marketing. It simply means the marketing landscape is now ripe for further tech disruption, and the protocols for this disruption are clear – it has to be privacy first.”</p><p>Trustworthiness (83%), integrity (79%) and honesty (77%) are the key emotional elements consumers feel most align with their favourite brands, according to Deloitte Digital. The persistence of cookies has arguably undermined these principles, but will Google's move to ban them deliver the trust and transparency consumers crave?</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media" data-original-url="/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media">The future of AI in advertising and media</a></p></div></div><p>Lior Charka, VP of product at Outbrain, agrees the kind of marketing messages that will need to be created post-cookie must be different: "Business marketing teams must recognise this, consequently making smart adjustments to their marketing mix to prioritise the delivery of engaging and relevant advertising experiences for users without using their personal data.”</p><p>Brute force use of consumer data to define marketing messages needs to be replaced with what's been called 'consent-driven engagement'. Suppose the data companies and marketers have relied upon disappears. In that case, they need to replace this information to maintain the commercial relationships they have spent, in some cases, high levels of resources to obtain. Shifting to more efficiently using first-party cookies, though, may benefit businesses as this strategy would require much closer direct connections with customers.</p><p>“Research from our Deloitte Global Marketing Trends 2022 report found that more than 60% of high-growth brands are shifting to a first-party data strategy compared to just over half of low-growth and 40% for negative-growth companies", William Grobel, director in Deloitte Digital, tells <em>IT Pro</em>. “There is, therefore, a clear link between growth and owning your own customer data." </p><p>Grobel continues: “Unsurprisingly, high growth organisations are also more creative in how they use first-party data. For example, when asking <a href="https://www.itpro.com/strategy/28225/cmo-job-description-what-does-a-cmo-do" target="_blank" data-original-url="https://www.itpro.com/strategy/28225/cmo-job-description-what-does-a-cmo-do">chief marketing officers (CMOs)</a> what they are using first-party data for, most organisations claim to use it for optimising emails and personalisation. Meanwhile, high-growth organisations also use first-party data for more advanced activities such as dynamic creative optimisation.”</p><h2 id="preparing-for-a-brave-new-cookie-free-world">Preparing for a brave new cookie-free world</h2><p>Since the advent of <a href="https://www.itpro.com/policy-legislation/information-commissioner/367179/ico-chief-warns-ministers-against-ditching-gdpr" data-original-url="https://www.itpro.com/policy-legislation/information-commissioner/367179/ico-chief-warns-ministers-against-ditching-gdpr">GDPR</a>, which is designed to protect the privacy of individuals when they use digital services, the debate whether the giant data aggregators have become too powerful and how personal data is collected, stored, shared and used for not just marketing messages, but to profile the behaviour of every user has crescendoed.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/361656/ico-publishes-new-data-protection-standards-for-the" data-original-url="/policy-legislation/data-protection/361656/ico-publishes-new-data-protection-standards-for-the">ICO publishes new data protection standards for the adtech industry</a></p></div></div><p>Google’s approach is to remove the individuality of targeted ads with consumers being placed in larger cohort groups who've expressed similar interests and have similar digital footprints. Testing has been underway with Federated Learning of Cohorts (FLoC) in readiness for the official sunsetting of third-party cookies. This, however, has run into regulatory hurdles, with <a href="https://www.itpro.com/mobile/google-android/362288/google-brings-privacy-sandbox-initiative-to-android" data-original-url="https://www.itpro.com/mobile/google-android/362288/google-brings-privacy-sandbox-initiative-to-android">Google forced to compromise on its initial programme</a> and replace it with a proposal called Topics.<strong> </strong></p><p>A return to traditional mechanisms is also likely as brands collect their own data and use those insights to target their messaging. Expect to see more websites insist on account creation, so they can track interactions by compelling users to log on.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SZN2UouDL2uLS4XNrCFvy8" name="SZN2UouDL2uLS4XNrCFvy8.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/SZN2UouDL2uLS4XNrCFvy8.jpg" mos="https://cdn.mos.cms.futurecdn.net/SZN2UouDL2uLS4XNrCFvy8.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Navigate disruption and drive positive business outcomes with cloud migration</strong></p><p class="fancy-box__body-text">Build highly resilient, efficient digital business models through the cloud</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/367532/navigate-disruption-and-drive-positive-business-outcomes-with-cloud-migration" data-original-url="/cloud/367532/navigate-disruption-and-drive-positive-business-outcomes-with-cloud-migration">FREE DOWNLOAD</a></p></div></div><p>For consumers, this might deliver the control they want, as they'll need to consent to each cookie being installed on their devices. Brands, however, will be pushed to do better and show that the value exchange of data for goods or services is worth the cookie consent.</p><p>“It’s important to remember that the entire freemium economy is based on advertising,” Outbrain’s Lior Charka points out. “When users opt-out of sharing data, they receive less personalised advertising which in turn leads to lower CPMs and the need for more sites to switch to subscription models. So, there is a big trade-off when we incorporate more privacy laws. It’s one that consumers will need to consider down the road.”</p><p>Lastly, some form of digital fingerprinting could be adopted. Here, the browser, language and even keyboard layout can be identified. This digital profile of an individual can then be used to track them across the web, giving marketers all the information they need to target their ads.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/64lZDZ42OOQI9WbUSEulD9"></iframe><p>Businesses can check their reliance on third-party cookies with the <a href="https://www.deloittedigital.com/us/en/offerings/customer-led-marketing/advertising--marketing-and-commerce/Cookieless-Calculator.html">Cookieless Calculator</a> developed by Gartner. “This identifies an organisation’s reliance on third-party cookies, assesses the potential impact and identifies mitigations and strategies to manage the transition," the company explains to <em>IT Pro</em>. "Across these assessments we found that an average of nearly 70% of website tags have a medium-to-high reliance on third-party cookies; 45% of digital media investments could be impacted and over half of all cookies used will be impacted – so there are some material consequences.”</p><p>Will the end of the third-party cookie push marketers into paying more attention to the security and privacy concerns of the people they target? That's undoubtedly the intention Google would like to communicate loudly. With the demise of third-party cookies fast approaching, what could replace them is, hopefully, a deeper understanding of customer needs and a fair exchange of personal data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google to add more Workspace data transfer controls in Europe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/367575/google-to-add-more-workspace-data-transfer-controls</link>
                                                                            <description>
                            <![CDATA[ Tech giant to offer "Sovereign Controls" in 2022 and 2023 to help navigate the "evolving" data landscape ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">79dHgUJrpNfhqKRLYhuHoZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dr45Br6o22iFciyf5YYPK6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 May 2022 10:16:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dr45Br6o22iFciyf5YYPK6-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google&amp;#039;s Workspace suite on a smartphone]]></media:description>                                                            <media:text><![CDATA[Google&amp;#039;s Workspace suite on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[Google&amp;#039;s Workspace suite on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dr45Br6o22iFciyf5YYPK6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has announced a set of new data transfer controls for its Workspace productivity suite, which will be rolled out in Europe starting this year. </p><p>The controls will enable organisations in both the public and private sectors to "control, limit and monitor" transfers of data to and from the European Union, according to the tech giant's blog.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement" data-original-url="/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement">EU and US reach agreement on Privacy Shield replacement</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/collaboration/367272/google-workspace-update-meet-calls-docs-sheets" data-original-url="/business-strategy/collaboration/367272/google-workspace-update-meet-calls-docs-sheets">Google Workspace update adds Meet calls to Docs and Sheets, chat threads to Spaces</a></p></div></div><p>Heightened legal risk around the export of personal data appears to be the motivation behind the changes, with <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" target="_blank" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield#:~:text=Privacy%20Shield%20was%20a%20regulatory,Union%20and%20the%20United%20States.">landmark EU rulings in 2020 heavily affecting regional use of US cloud services</a>. It is certainly the reason behind Google's "Sovereign Controls for <a href="https://www.itpro.com/business-operations/productivity/357340/google-workspace-merges-the-g-suite-into-single-platform" target="_blank" data-original-url="https://www.itpro.com/business-operations/productivity/357340/google-workspace-merges-the-g-suite-into-single-platform">Google Workspace</a>" terminology, which seems to have been directly taken from the "digital sovereignty" that EU lawmakers referred to. </p><p>The new controls will start rolling out at the end of 2022, with additional capabilities to be delivered throughout 2023. Google said it will build on its commitment to "Client-side encryption", "Data regions", and "Access Controls" capabilities. </p><p>"European organisations are moving their operations and data to the cloud in increasing numbers to enable collaboration, drive business value, and transition to hybrid work. However, the cloud solutions that underpin these powerful capabilities must meet an organisation's critical requirements for security, privacy, and digital sovereignty," Google's VP and GM of Workspace, Javier Soltero wrote in a blog post.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qocoaMhXdMqCEQS5VRtBUN" name="qocoaMhXdMqCEQS5VRtBUN.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/qocoaMhXdMqCEQS5VRtBUN.jpg" mos="https://cdn.mos.cms.futurecdn.net/qocoaMhXdMqCEQS5VRtBUN.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How the cloud helps cities become sustainable and inclusive</strong></p><p class="fancy-box__body-text">The technology transforming our environments to make them work for everyone</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/smart-city/367522/how-the-cloud-helps-cities-become-sustainable-and-inclusive" data-original-url="/technology/smart-city/367522/how-the-cloud-helps-cities-become-sustainable-and-inclusive">FREE DOWNLOAD</a></p></div></div><p>"We often hear from European Union policymakers and business leaders that ensuring the sovereignty of their cloud data, through regionalisation and additional controls over administrative access, is crucial in this evolving landscape."</p><p>Organisations can opt to use <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it" target="_blank" data-original-url="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it">"client-side" encryption</a>, according to Soltero. It is now generally available for Google Drive, Docs, Sheets and Slides, with plans to extend it to Gmail, Calendar and Meet by the end of the year. </p><p>Beyond that, the tech giant is also expanding data location controls by the end of 2023 and more access controls. This will include capabilities to restrict or approve Google support access through 'Access Approvals". The ability to limit customer support to EU-based staff through 'Access management and functions to generate "comprehensive" log reports on data access via an Access Transparency feature. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU rules against Meta in data privacy row ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/367545/eu-rules-against-meta-in-data-privacy-row</link>
                                                                            <description>
                            <![CDATA[ The European Court of Justice (CJEU) says consumer groups can take legal action over data privacy breaches ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wDwvPE5GtzYUUfLiXXs5xn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y9D7nRU5SSP6x2cyxj6kba-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 Apr 2022 11:30:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y9D7nRU5SSP6x2cyxj6kba-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A smartphone lying on a laptop displaying the Meta company logo]]></media:description>                                                            <media:text><![CDATA[A smartphone lying on a laptop displaying the Meta company logo]]></media:text>
                                <media:title type="plain"><![CDATA[A smartphone lying on a laptop displaying the Meta company logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y9D7nRU5SSP6x2cyxj6kba-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Court of Justice (CJEU) has ruled that Germany’s consumer protection association can bring a legal challenge against Meta over data privacy breaches. </p><p>The Federal Court of Justice in Germany (Bundesgerichtshof), asked the EU’s highest court whether consumer groups could take legal action over <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data privacy infringements</a>, or whether these issues were to be tackled by national supervisory authorities.</p><p>In response, the CJEU ruled in favour of the possibility, explaining that “it pursues a public interest objective consisting in safeguarding the rights and freedoms of data subjects in their capacity as consumers” according to <a href="https://www.courthousenews.com/german-consumer-watchdog-can-sue-meta-top-eu-court-rules" target="_blank"><em>Court House News</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" data-original-url="/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">The risks and strategies of using privacy as a business differentiator</a> General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/361396/meta-industry-reacts-to-the-facebook-companys-rebrand" data-original-url="/business/business-strategy/361396/meta-industry-reacts-to-the-facebook-companys-rebrand">'Changing name to Meat': Industry reacts to Facebook's Meta rebrand</a></p></div></div><p>The ruling means the Federation of German Consumer Organisations and Associations (VZBV) can apply for an injunction against Meta Platforms Ireland in a German court. </p><p>The development follows the German consumer group’s allegation that Meta infringed rules on data privacy and unfair competition regulations enabling free third-party games to collect personal data from users. </p><p>Ultimately, users clicking “play now” on games such as Scrabble on Facebook were inadvertently consenting to their data being collected by the game creators.</p><p>The German court asked the CJEU whether the EU’s data protection laws of 2018 would allow a consumer body to take legal action over such infringements, or whether national supervisory authorities were to handle the matter. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="P4x3aTyhBQEcKQEtDASEAC" name="P4x3aTyhBQEcKQEtDASEAC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/P4x3aTyhBQEcKQEtDASEAC.png" mos="https://cdn.mos.cms.futurecdn.net/P4x3aTyhBQEcKQEtDASEAC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Microsoft 365 protection made MSPEasy</strong></p><p class="fancy-box__body-text">The cloud protection solution built for MSPs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367295/microsoft-365-protection-made-mspeasy" data-original-url="/security/367295/microsoft-365-protection-made-mspeasy">FREE DOWNLOAD</a></p></div></div><p>The German court found the consumer protection association’s complaint credible but did question its admissibility. The EU court ruled that under GDPR, the complaint is valid, adding that consumer associations qualify as bodies able to bring GDPR proceedings as they would be acting in the public’s interest. </p><p>In a statement, Ursula Pachl, deputy director-general of the European Consumer Organisation, which includes VZBV, praised the ruling.</p><p>“The GDPR is a crucial law that protects people’s personal data in the EU,” she said. “It is essential that it is better enforced, and rulings like today’s will help.”</p><p>A spokesperson for Meta said the company would review the decision. “The underlying legal proceedings showed that there were some open questions, which the CJEU has now addressed," they said. "We will review the decision and assess its implications."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google adds "reject all" cookie buttons to appease EU regulators ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/367468/google-adds-reject-all-cookie-buttons-to-appease-eu</link>
                                                                            <description>
                            <![CDATA[ New banners will be applied to Search and YouTube in France before rolling out across Europe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">veBfdmMFcVvnuyftipZaTV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YG7mMatnoCbHEnHJBPhSEG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Apr 2022 10:28:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YG7mMatnoCbHEnHJBPhSEG-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Google logo on a smartphone display ]]></media:description>                                                            <media:text><![CDATA[The Google logo on a smartphone display ]]></media:text>
                                <media:title type="plain"><![CDATA[The Google logo on a smartphone display ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YG7mMatnoCbHEnHJBPhSEG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google is introducing new options to reject tracking cookies in Europe after EU regulators found its existing pop-ups to be in violation of its data laws. </p><p>The new cookie banners will give 'clear' and 'balanced' choices, the tech giant said, though most Google users might not notice the change. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/361576/what-are-cookies" data-original-url="/security/361576/what-are-cookies">What are cookies</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/361913/france-fines-google-facebook-over-cookie-policies" data-original-url="/business/policy-legislation/361913/france-fines-google-facebook-over-cookie-policies">Google, Facebook fined €210 million for making it difficult for users to reject cookies</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358637/what-are-supercookies" data-original-url="/security/privacy/358637/what-are-supercookies">What are supercookies?</a></p></div></div><p>For anyone using Google Search or YouTube in Europe (while signed out or within the incognito mode), there will be "equal" choices with 'reject all' and 'accept all' buttons on the first screen. Users can also select a "more options" button to customised their level of consent. The buttons have been launched in France and will soon be seen across the rest of the European Economic Area - including the UK and Switzerland.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CeaSonN8RgCHCvAbZd897b" name="" alt="Google's new "reject all" cookie option" src="https://cdn.mos.cms.futurecdn.net/CeaSonN8RgCHCvAbZd897b.png" mos="https://cdn.mos.cms.futurecdn.net/CeaSonN8RgCHCvAbZd897b.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Google Blog)</span></figcaption></figure><p>The use of <a href="https://www.itpro.com/security/361576/what-are-cookies" target="_blank" data-original-url="https://www.itpro.com/security/361576/what-are-cookies#:~:text=In%20short%2C%20a%20cookie%20is,as%20you%20use%20the%20internet.">cookies banners</a>, in general, is far from ideal as it still remains a muddled and frustrating experience for most web users. For Google specifically, many users simply won't see the updated popup as it will only work if they are logged out of Google accounts, as they'll most likely have their settings already stored. In essence, this new banner is largely going to be used by those without a Google account. </p><p>The move follows a <a href="https://www.itpro.com/business/policy-legislation/361913/france-fines-google-facebook-over-cookie-policies" target="_blank" data-original-url="https://www.itpro.com/business/policy-legislation/361913/france-fines-google-facebook-over-cookie-policies">€150 million fine from the French data protection agency</a> (CNIL), which found Google's cookie banners to have confusing language. Google previously allowed users to accept all tracking cookies with a single click, but it would then direct users through extra steps to "reject all". CNIL said this was unlawful as it forced users into accepting <a href="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law" target="_blank" data-original-url="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law">cookies</a> for the benefit of Google's advertising business.</p><p>"Based on these conversations and specific direction from France's Commission Nationale de l'Informatique et des Libertés (CNIL), we have now completed a full redesign of our approach, including changes to the infrastructure we use to handle cookies," Google's product manager of privacy, safety and security, Sammit Adhya said in a blog post.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data protection by design isn’t just a buzzphrase you can ignore  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/367430/data-protection-by-design-isnt-just-a-buzzphrase</link>
                                                                            <description>
                            <![CDATA[ This principle should guide you on every step of a customer’s journey because, if you get it wrong, you could land on the wrong side of the law ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2LA1YRm5hjzn9AihkX3DPK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/q4YUczoPpGunXWeN5RBWDH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 16 Apr 2022 07:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Olivia Whitcroft ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/q4YUczoPpGunXWeN5RBWDH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image showing three purple padlocks stacked on top of each other in front of lines of code]]></media:description>                                                            <media:text><![CDATA[Abstract image showing three purple padlocks stacked on top of each other in front of lines of code]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image showing three purple padlocks stacked on top of each other in front of lines of code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/q4YUczoPpGunXWeN5RBWDH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Let me tell you a story: You’re having a new friend round for lunch. You designed a recipe for a “Meaty Platter”, which combines a range of meats, to create the perfect meaty experience. Over the last week, you have purchased the finest ingredients for each component of the platter. That morning you blend it all together and make it look amazing. Your friend presses the doorbell and enters your home. She takes one look at your beautiful platter and declines to eat it; she doesn’t understand what it’s made from, and she doesn’t want to eat meat. Meaty Platter goes in the bin, and your friend doesn’t return, or, alternatively, maybe she takes a taste and then suffers a severe stomach ache later that day, and your friendship is lost. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DfPkXvU2kswi3wVfaLtMcK" name="DfPkXvU2kswi3wVfaLtMcK.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/DfPkXvU2kswi3wVfaLtMcK.jpg" mos="https://cdn.mos.cms.futurecdn.net/DfPkXvU2kswi3wVfaLtMcK.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ of IBM Spectrum Virtualize</strong></p><p class="fancy-box__body-text">Cost savings and business benefits enabled by storage built with IBMSpectrum Virtualize</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/server-storage/360179/the-total-economic-impacttm-of-ibm-spectrum-virtualize" data-original-url="/infrastructure/server-storage/360179/the-total-economic-impacttm-of-ibm-spectrum-virtualize">FREE DOWNLOAD</a></p></div></div><p>So, how do you host a lunch without alienating or damaging your friends? Before designing your recipe, you consider whether aspects of your menu may use ingredients unsuitable for some guests. You could also ask your guests if they have any dietary concerns. Any issues can then be addressed within your recipe and the ingredients that form part of it. You can prepare a tailored platter with all dietary needs baked into it. You can let guests know what it is, so they can make an informed decision about whether to eat it. In my story, you could then present your friend with a meal she understands and wants to eat. Meaty Platter (perhaps now Veggie Platter) hopefully won’t be thrown in the bin. If your friend takes a taste, she’s less likely to suffer a stomach ache, and you’re more likely to retain your friendship.</p><p>You may not be able to eliminate every risk. You’re unlikely to have considered all potential eventualities or have discussed with every guest the full detail of your menu. A guest may have an unforeseen dislike of a particular ingredient, or a previously unknown allergy. But, by considering the risks in advance, and without taking unnecessary steps to guarantee a fault-free meal, you have minimised the risk that a dietary issue leads to your food not being eaten, or causes damage to your guests. </p><h2 id="the-story-re-told">The story re-told</h2><p>Let me tell you another story: You’re launching a new technology product. You designed a recipe for “Meeting Platform”, which combines a range of information about customers’ online habits, to create the perfect meeting experience. Over the past year, you’ve engaged the finest coders for each component of the platform. That month, you have been blending it all together and making it look good. You press the launch button (there’s always a big launch button, right?), and your customers enter your platform. They take one look at your beautiful product and decline to use it; they don’t understand what you do with the requested data, and they don’t want to provide it. Meeting Platform is shelved, and your customers don’t return, or, alternatively, maybe some customers take a taste, and then you suffer a severe <a href="http://Ten%20ways%20to%20protect%20your%20company%20from%20the%20next%20big%20data%20breach" target="_blank">security breach</a> later that week, and customer data is lost.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" data-original-url="/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">Ten ways to protect your company from the next big data breach</a></p></div></div><p>So, how do you launch a product without alienating or damaging your customers? Before designing your platform, you consider whether aspects of your product may use personal data. You could also ask potential customers if they have any concerns with the use of their data. Any issues can then be addressed within your platform, and the components that form part of it. You can prepare a tailored platform with data protection baked into it. You can let customers know what you’ll do with their data, so they can make an informed decision about whether to use it. In my story, you could then present customers with a product they understand and want to use. Meeting Platform hopefully won’t be shelved. If your customers take a taste, you’re less likely to suffer a security breach, and you are more likely to retain your customers. </p><p>You may not be able to eliminate every risk. You’re unlikely to have considered all potential eventualities, or to have discussed with every customer the full detail of the platform’s use of personal data. A customer may have an unforeseen dislike to a particular use of data, or the system may have a previously unknown vulnerability. But, by considering the risks in advance, and without taking disproportionate steps to guarantee a fault-free product, you have minimised the risk that a data protection issue leads to your product not being used, or causes damage to your customers. </p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/LuqAVA1jiPI" allowfullscreen></iframe></div></div><h2 id="data-protection-by-design">Data protection by design</h2><p>Data protection by design is just this! It’s about baking data protection compliance into the design and development of new activities involving the use of personal data. All data protection requirements should be addressed, including the core principles (such as transparency, data minimisation and <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">security</a>), and enabling individuals to exercise their rights (such as the right to access and erase data). </p><p>Data protection by design is a legal requirement under UK GDPR, along with the closely related concept of data protection by default. This demands that the default position for any activity is to collect the minimum amount of data and do the minimum amount of processing. The obligations are ongoing throughout the lifecycle of the use of data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready" data-original-url="/general-data-protection-regulation-gdpr/30107/get-gdpr-ready">Seven steps to GDPR compliance</a></p></div></div><p>Without data protection by design, data protection may only be an afterthought for a project (by which time it may be too late to address issues), or it may be ignored completely. This may lead to the project being shelved for data protection reasons. As a topical example, the <a href="https://www.itpro.com/policy-legislation/data-protection/356503/government-admits-breaking-gdpr-laws-in-nhs-track-and" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/356503/government-admits-breaking-gdpr-laws-in-nhs-track-and">NHS COVID-19 app</a> faced several data-protection hurdles. <a href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">Privacy</a> concerns were key to the UK government scrapping the original 2020 centralised model, and, in 2021, it was reported that an update to the app had been blocked by Apple and Google due to the prohibited collection of location data. </p><p>Even if a project isn’t cancelled, it could cause significant costs and delays to rework it to address data protection issues. In May 2019, the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> issued an enforcement notice against HMRC in relation to its Voice ID service, requiring it to delete data. The ICO found <a href="https://www.itpro.com/data-protection/31371/hmrc-disregards-data-protection-collecting-5m-uk-citizens-voice-recordings" target="_blank" data-original-url="https://www.itpro.com/data-protection/31371/hmrc-disregards-data-protection-collecting-5m-uk-citizens-voice-recordings">HMRC was processing biometric data</a> (for voice authentication) without a lawful basis under data protection law, as it had failed to obtain adequate consent. In its notice, the ICO stated: “HMRC appears to have given little or no consideration to the data protection principles when rolling out the Voice ID service.” In other words, it didn’t apply data protection by design. </p><h2 id="when-is-it-needed">When is it needed?</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nJTt7CBdokYFK7EPEx65UQ" name="nJTt7CBdokYFK7EPEx65UQ.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nJTt7CBdokYFK7EPEx65UQ.jpg" mos="https://cdn.mos.cms.futurecdn.net/nJTt7CBdokYFK7EPEx65UQ.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Why smart businesses view a data fabric as an inevitable approach to becoming data driven</strong></p><p class="fancy-box__body-text">Adopting a data-driven strategy for success</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-management/362125/why-smart-businesses-view-a-data-fabric-as-an-inevitable" data-original-url="/data-insights/data-management/362125/why-smart-businesses-view-a-data-fabric-as-an-inevitable">FREE DOWNLOAD</a></p></div></div><p>Data protection by design most obviously springs to mind for big projects, such as new technology systems that will process personal data. Its remit, however, is much wider than this. It applies to all activities involving personal data (big or small), and to the preparation of <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">policies and processes that govern the use of data</a>. You may not need to carry out the same level of review in each case, though. As raised in my stories, the approach you take and the extent of measures you put in place should be proportionate to the risks involved.</p><p>Consider, for example, a business’s use of customer contact details to keep customers updated about requested services. Design measures may include ensuring customer details aren’t used for a wider purpose, and are kept up to date and secure from misuse. However, the assessment may be fairly quick, and the measures fairly standard. Compare this with more innovative or intrusive uses of data, such as those involving artificial intelligence, sensitive data, or monitoring and profiling of individuals. A more complex assessment and more bespoke design measures are likely to be needed. For these types of higher-risk activities, a formal data protection impact assessment (DPIA) may be needed, and it forms an important part of data protection by design. Asking those who will be impacted for their views, is also a stage of the DPIA process.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr" data-original-url="/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr">How to perform a data protection impact assessment (DPIA) under GDPR</a></p></div></div><p>In my experience, higher-risk projects are commonly now given some quality data-protection time, although I still come across some clangers. Just the other day, a company sent its employees a request to provide their COVID-19 vaccination details, together with proof of vaccination (with type of vaccine and dates), or the reason why they were unvaccinated. The request had no explanation as to what would be done with this information. My head started firing out data protection principles: There was no transparency or specified purpose! What was the lawful basis? How about data minimisation?</p><p>At the lower-risk end of the spectrum, I find there is a tendency to focus on specific aspects of compliance (such as having a privacy notice, and checking security measures), without looking at the full range of data protection design elements. As an example, one of my clients recently launched a new website, and included a form for people to sign up to receive a newsletter. However, there was no newsletter – this request was “just in case” the company decided to create one in the future. Data protection by default, and the principle of data minimisation, would say don’t collect this information yet, as it’s not needed right now.</p><h2 id="privacy-enhancing-technologies">Privacy-enhancing technologies</h2><p>The organisations actually collecting and handling personal data have legal responsibilities under data protection law. However, product developers have a role in designing systems with data protection embedded, which can also be a selling point for them. This is the aim of ‘privacy-enhancing technologies’, meaning technologies that are designed for supporting specific privacy or data protection functionality, or protecting against privacy risks. They’re currently a hot topic in the data protection world.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=46975747&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>I have excitedly been trying to understand mathematical concepts such as differential privacy (adding ‘noise’ to statistics to make it more difficult to identify source data), and homomorphic encryption (which enables functions to be carried out on specific data without decrypting whole data sets). Anonymisation and pseudonymisation functionality can also be built into technology design. These types of privacy-enhancing measures may most obviously assist with information security, but they have wider data protection benefits. They may, for example, limit retention periods by ensuring individuals can no longer be identified from data sets, ensure that only the minimum amount of personal data is held within a system, and facilitate the exercise of rights by data subjects. </p><p>So next time you’re designing your recipe for new technology or data processing activities – or even a meaty platter – don’t forget to bake in your data protection (or dietary) requirements.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the ECJ's metadata ruling endangers the safety of women ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/367362/ecj-metadata-ruling-violence-against-women</link>
                                                                            <description>
                            <![CDATA[ Until we live in a society in which women are safe, we might need to compromise on mass data collection ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">egpKPwdbHfVV6qm36XiTg8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VJ8yU2SjrDtCJmsB5CSA5n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Apr 2022 16:10:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VJ8yU2SjrDtCJmsB5CSA5n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The ECJ building exterior in Luxemburg]]></media:description>                                                            <media:text><![CDATA[The ECJ building exterior in Luxemburg]]></media:text>
                                <media:title type="plain"><![CDATA[The ECJ building exterior in Luxemburg]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VJ8yU2SjrDtCJmsB5CSA5n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In a major ruling this Tuesday, the European Court of Justice (ECJ) effectively banned the use of retained communications data, or metadata, in solving crimes that aren’t deemed a threat to national security. A big win for democratic rights across the EU? Yes – but not if you’re a woman.</p><p>In its <a href="https://curia.europa.eu/juris/document/document.jsf?text=&docid=257242&pageIndex=0&doclang=EN&mode=req&dir=&occ=first&part=1">landmark judgement</a>, the ECJ ruled in favour of Irishman Graham Dwyer who, in 2015, was convicted of the 2012 murder of Elaine O'Hara. Described by prosecutors as “very nearly the perfect murder” due to the lack of both witnesses and material evidence, Dwyer would have gotten away with it, if not for his phone records, which tied him to the crime scene. The main rationale, according to the ECJ, is that mass and indiscriminate <a href="https://www.itpro.com/business-operations/31681/what-is-data-processing" target="_blank" data-original-url="https://www.itpro.com/business-operations/31681/what-is-data-processing">data collection</a> – and retention – isn’t compatible with living in a democratic society. Because Dwyer’s phone records were derived through this practice, it may render this key piece of evidence potentially inadmissible. Although I’m a firm believer in citizens’ right to <a href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">privacy</a>, including when it comes to their data, this decision has made me anxious about the safety of women in wider society. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies" data-original-url="/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies">The risks and strategies of using privacy as a business differentiator</a></p></div></div><p>The ruling, of course, doesn’t apply to investigating terrorist attacks, with the ECJ claiming criminal behaviour, even serious in nature, cannot be treated in the same way as a threat to national security. Estimates, however, show femicides are roughly <a href="https://www.statista.com/statistics/1096116/femicide-in-europe-in-2018">ten times more prevalent</a> than terrorism in the EU. What’s more, while terrorist attacks in Europe <a href="https://reliefweb.int/report/world/global-terrorism-index-2022">dropped by 68% between 2018 and 2021</a>, several EU member states, including <a href="https://www.euractiv.com/section/politics/short_news/italys-femicide-rates-increased-during-pandemic">Italy</a>, <a href="https://www.france24.com/en/tv-shows/reporters/20220304-femicide-in-germany-a-silent-epidemic">Germany</a>, and <a href="https://www.amnesty.org/en/latest/news/2020/07/while-tackling-covid-19-europe-is-being-stalked-by-a-shadow-pandemic-domestic-violence">Poland</a>, reported significant increases in violence against women <a href="https://www.unwomen.org/en/news/in-focus/in-focus-gender-equality-in-covid-19-response/violence-against-women-during-covid-19">since the start of the pandemic</a>.</p><p>While the ECJ ruling, in theory, protects us from overreaching law enforcement agencies, the fact it’s willing to make an exception for one type of crime, but not another, sends a clear message that violence against women is simply not as important. Moreover, it raises the question as to whether Dwyer will now be allowed to walk free, and how this could embolden mens’ attempts to get away with murder – literally. Worse yet, the ruling may hinder ongoing investigations into femicide – and perhaps dredge up historic cases, too, in which data retention issues applied.</p><p>It’s especially disheartening considering 2021 murders of my fellow Londoners – marketing executive Sarah Everard and primary school teacher Sabina Nessa. I’ve always partaken in the practice of texting friends to make sure they got home okay, or even asking male friends to escort me. These two incidents, though, have heightened our feeling that we’re risking our lives by simply going to the pub, walking home from a friend’s house, or even going for an afternoon run, as was the case with Irish primary school teacher Ashling Murphy earlier this year. Everard’s case is particularly poignant. Her killer, police officer Wayne Couzens, was tied to the location of Everard's disappearance, as well as the area her body was found, using cell site data, which identifies a phone’s location at a specific time.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state" data-original-url="/security/privacy/361191/is-australia-becoming-a-surveillance-state">Is Australia becoming a surveillance state?</a></p></div></div><p>What would happen if, similarly to the Dwyer case, the incriminating <a href="https://www.itpro.com/cloud/cloud-storage/364172/what-is-object-storage" target="_blank" data-original-url="https://www.itpro.com/cloud/cloud-storage/364172/what-is-object-storage">metadata</a> was found several years – as opposed to several days – after her disappearance, but provisions blocked it from being used? If not for the additional CCTV footage used to prosecute Couzens, based on the ECJ’s ruling, should he simply be allowed to walk free? If one of the world's most influential courts can't be flexible enough to incorporate womens' safety into their legal judgements, which entity is supposed to protect us as human beings? I agree with the ECJ that data privacy is an inherent right in a democratic society, but it's an idealistic view that goes against our reality. While that same society is capable of raising men to abduct, rape, and murder women, we might need to make compromises on how <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">privacy</a> and data retention are seen.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU and US reach agreement on Privacy Shield replacement ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement</link>
                                                                            <description>
                            <![CDATA[ Privacy campaigner Max Schrems suggests the deal amounts to a "patchwork approach" that will ultimately fail ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6Y4J1e8n5Z9JSfK4aKtuM6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Mar 2022 13:04:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image showing EU and US flags tiled together]]></media:description>                                                            <media:text><![CDATA[Abstract image showing EU and US flags tiled together]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image showing EU and US flags tiled together]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/s8Po9CcKH6yBWVd6GQp2bh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Union and the US government have reached an agreement, in principle, on a deal for transatlantic data flows.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/363776/aws-says-customers-dont-have-to-use-privacy-shield" data-original-url="/security/privacy/363776/aws-says-customers-dont-have-to-use-privacy-shield">AWS says customers don’t have to use Privacy Shield</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu" data-original-url="/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu">EU and UK reach post-Brexit data flows deal</a></p></div></div><p>A new agreement potentially signals an end to years of legal uncertainty that has hung over the US, particularly its <a href="https://www.itpro.com/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal" target="_blank" data-original-url="https://www.itpro.com/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal">tech industry</a>, since the EU-US Privacy Shield mechanism was invalidated in a <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" target="_blank" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">2020 court ruling</a>.</p><p>EU president Ursula von der Leyen revealed the proposed deal during a joint briefing with US president Joe Biden, who is in Europe mainly to discuss the Russian invasion of Ukraine. Von der Leyen gave special thanks to EU justice commissioner Didier Reynders and US secretary of commerce Gina Raimondo for their efforts in finding an effective solution. However, the exact details of the agreement, specifically what each party has agreed to, have not been clearly explained.</p><p>"I am very pleased that we have found an agreement in principle on a new framework for transatlantic data flows," said von der Leyen. "This will enable predictable and trustworthy data flows between the EU and US, safeguarding privacy and civil liberties."</p><p><a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" target="_blank" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> was deemed incompatible with the EU's data protection laws, largely due to the American government's own regulations for surveillance. A European Court of Justice ruling in 2020 found the act was unable to uphold the levels of privacy that data subjects in Europe are legally entitled to.</p><p>"We managed to balance security and the right to privacy and data protection," von der Leyen suggested during the briefing.</p><p>However, some have criticised what's seen as an impossible task of reconciling two different data protection approaches, particularly as the US has yet to enact a federal data protection policy.</p><p>In response, Max Schrems, the privacy lawyer and campaigner behind the <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">Schrems I and Schrems II legal cases</a>, took to Twitter to question the weight of the deal.</p><p>"Seems we do another Privacy Shield especially in one respect: Politics over law and fundamental rights," he tweeted. "This failed twice before. What we heard is another 'patchwork' approach but no substantial reform on the US side. Let's wait for a text but my bet is it will fail again."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta hit with €17 million fine over multiple GDPR breaches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/366996/meta-fine-gdpr-breaches</link>
                                                                            <description>
                            <![CDATA[ The social media giant set aside over €1 billion in November to help it cope with potential fines arising from data protection investigations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jWjugYoapa2zSN8qS5YWsj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k3irTs7PxoYDQoFyWzx8Ad-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Mar 2022 11:33:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k3irTs7PxoYDQoFyWzx8Ad-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A smartphone showing the Meta company logo in front of a large Facebook logo]]></media:description>                                                            <media:text><![CDATA[A smartphone showing the Meta company logo in front of a large Facebook logo]]></media:text>
                                <media:title type="plain"><![CDATA[A smartphone showing the Meta company logo in front of a large Facebook logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k3irTs7PxoYDQoFyWzx8Ad-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ireland’s <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">Data Protection</a> Commission (DPC) has hit <a href="https://www.itpro.com/tag/facebook" target="_blank" data-original-url="https://www.itpro.com/search/meta">Meta</a> with a €17 million (£14 million) fine over multiple breaches of GDPR. </p><p>The DPC said the decision followed an inquiry into a series of 12 data breach notifications it received between 7 June 2018 and 4 December 2018. The inquiry looked at the extent to which Meta complied with the requirements of GDPR Articles 5(1)(f), 5(2), 24(1) and 32(1) in relation to the processing of personal data relevant to the 12 breach notifications.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/360936/irish-dpc-facebook-smart-glasses-privacy-concerns" data-original-url="/security/privacy/360936/irish-dpc-facebook-smart-glasses-privacy-concerns">Irish DPC threatens probe over Facebook’s Ray-Ban smart glasses</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to">Irish data regulator fails to resolve 98% of big tech GDPR cases</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/361667/google-settles-tax-payment-in-ireland" data-original-url="/business/361667/google-settles-tax-payment-in-ireland">Google settles tax payment in Ireland</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/361333/uk-to-scrap-digital-services-tax-by-2023" data-original-url="/business/policy-legislation/361333/uk-to-scrap-digital-services-tax-by-2023">UK agrees to scrap Digital Services Tax by 2023</a></p></div></div><p>Following the inquiry, the DPC found that Meta infringed Articles 5(2) and 24(1) GDPR. It found the company failed to have in place appropriate technical and organisational measures which would enable it to readily demonstrate the <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security">security</a> measures that it implemented in practice to protect EU users’ data, in the context of the 12 data breaches.</p><p>Since the processing under examination constituted “cross-border” processing, the DPC said its decision was subject to the co-decision making process outlined in Article 60 GDPR and all of the other European supervisory authorities were engaged as co-decision-makers.</p><p>The Irish data regulator has been accused in the past <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to">of being the “bottleneck” of GDPR enforcement</a> with 160 unresolved complaints. Campaigners claimed that it was hindering pan-European data protection enforcement as a result, with 98% of 164 cases remaining unresolved.</p><p>“While objections to the DPC’s draft decision were raised by two of the European supervisory authorities, consensus was achieved through further engagement between the DPC and the supervisory authorities concerned,” stated the DPC. “Accordingly, the DPC’s decision represents the collective views of both the DPC and its counterpart supervisory authorities throughout the EU.”</p><p>A Meta spokesperson told <em>IT Pro</em>: “This fine is about record-keeping practices from 2018 that we have since updated, not a failure to protect people's information. We take our obligations under the GDPR seriously, and will carefully consider this decision as our processes continue to evolve.”</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/OF298is2qoI" allowfullscreen></iframe></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xFhLBnz6SPY3nAo8DLnKXk" name="xFhLBnz6SPY3nAo8DLnKXk.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/xFhLBnz6SPY3nAo8DLnKXk.png" mos="https://cdn.mos.cms.futurecdn.net/xFhLBnz6SPY3nAo8DLnKXk.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Solving big data challenges with Multi-Cloud Data Services for Dell EMC PowerScale</strong></p><p class="fancy-box__body-text">Achieve cost-effective performance at scale and leverage multiple public clouds at the same</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/big-data/366426/solving-big-data-challenges-with-multi-cloud-data-services-for-dell" data-original-url="/data-insights/big-data/366426/solving-big-data-challenges-with-multi-cloud-data-services-for-dell">FREE DOWNLOAD</a></p></div></div><p>To put the €17 million fine into perspective, Facebook’s main Irish subsidiary paid an additional €35 million to settle outstanding tax matters in 2020, and the company put over €1 billion aside to cover potential fines from regulatory investigations, according to the <a href="https://www.irishtimes.com/business/technology/facebook-ireland-pays-35m-to-settle-tax-issues-and-sets-aside-1bn-for-possible-fines-1.4742716" target="_blank"><em>Irish Times</em></a>. Its corporate tax liability rose to €266.3 million from €173.2 million. Its revenue jumped by €6.3 billion to €40.6 billion at Facebook Ireland in 2020, while pre-tax profits rose to €890 million compared to €482 million the previous year.</p><p>The amount the company set aside for potential administrative fines from investigations conducted by data protection authorities more than tripled from €302.3 million to €1.02 billion. The company predicted that regulatory matters would be resolved within the next two years.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT Pro News In Review: UK four-day working week, cyber crime in schools, GDPR fines of €1bn in 2021 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/362031/uk-four-day-week-cyber-crime-in-schools-gdpr-fines-3-bn</link>
                                                                            <description>
                            <![CDATA[ Catch up on the biggest headlines of the week in just two minutes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7DgqdrMFuFFhHD3votUMWg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dfk66pUyJBNAg6Yg5UDodR-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Jan 2022 10:55:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/dfk66pUyJBNAg6Yg5UDodR-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT Pro News In Review: UK four-day working week, cyber crime in schools, EU GDPR fines of €1bn]]></media:description>                                                            <media:text><![CDATA[IT Pro News In Review: UK four-day working week, cyber crime in schools, EU GDPR fines of €1bn]]></media:text>
                                <media:title type="plain"><![CDATA[IT Pro News In Review: UK four-day working week, cyber crime in schools, EU GDPR fines of €1bn]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dfk66pUyJBNAg6Yg5UDodR-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/VzXDAWrKlPM" allowfullscreen></iframe></div></div><p>Welcome to IT Pro's News in Review, a weekly bite-sized bulletin of the top tech stories of the week, for the week ending 20 January, 2022.</p><p>This week's stories:</p><ul><li><a href="https://www.itpro.com/business/business-operations/361993/uk-pilots-four-day-working-week" data-original-url="https://www.itpro.com/business/business-operations/361993/uk-pilots-four-day-working-week">UK businesses urged to join four-day working week trial</a></li><li><a href="https://www.itpro.com/security/hacking/361997/nca-campaign-stop-children-cyber-crime" data-original-url="https://www.itpro.com/security/hacking/361997/nca-campaign-stop-children-cyber-crime">NCA plots education drive to crack down on children exploring cyber crime</a></li><li><a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/362000/european-data-regulators-issued" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/362000/european-data-regulators-issued">European data regulators issued €1.1 billion in GDPR fines in 2021</a></li></ul><p>You can find more videos like this in our video library and even more on <a href="https://www.youtube.com/user/itpro" rel="noopener" target="_blank">our YouTube channel</a>. Let us know what you think of this week's video – you can also find us on <a href="https://www.facebook.com/ITProUK" rel="noopener" target="_blank">Facebook</a>, <a href="https://www.linkedin.com/company/itpro-uk" rel="noopener" target="_blank">LinkedIn</a> and <a href="https://twitter.com/ITPro" rel="noopener" target="_blank">Twitter</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MoJ faces £17.5m GDPR fine over subject access request backlog ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/362025/moj-ps175m-fine-subject-access-request-backlog</link>
                                                                            <description>
                            <![CDATA[ The Information Commissioner's Office says the rights of data subjects are now being infringed by the processing delay ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8kdSUVfQ23JiAXkiHTcoWP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bN2c8M8qN5G35X3x4ZPX66-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Jan 2022 12:52:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bN2c8M8qN5G35X3x4ZPX66-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up shot of the Ministry of Justice sign outside its headquarters in London]]></media:description>                                                            <media:text><![CDATA[A close up shot of the Ministry of Justice sign outside its headquarters in London]]></media:text>
                                <media:title type="plain"><![CDATA[A close up shot of the Ministry of Justice sign outside its headquarters in London]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bN2c8M8qN5G35X3x4ZPX66-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's Ministry of Justice (MoJ) has been served an enforcement notice by the Information Commissioner's Office (ICO) for failing to address and respond to a growing backlog of Subject Access Requests (SARs).</p><p>The MoJ is said to have contravened Chapter 3, Article 15 of the EU and UK GDPR, and section 45 of the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act 2018</a>, and has now been ordered to develop a recovery plan that includes details of how to remedy the outstanding SARs, and "take appropriate steps" to ensure future SAR submissions are timely notified of any delays to a response.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules" data-original-url="/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules">UK government to consider gutting GDPR rules</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/31623/what-is-a-subject-access-request" data-original-url="/data-protection/31623/what-is-a-subject-access-request">What is a subject access request?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go" data-original-url="/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go">GDPR fines: Where does the money go?</a></p></div></div><p><a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">The ICO</a> said it issued the enforcement notice after considering, and agreeing, that "damage or distress is likely" as a result of the delay in SAR processing, which meant subjects were "being denied the opportunity of properly understanding what personal data may be being processed about them by the controller". Data subjects were also deemed to have been unable to exercise their statutory rights in respect to their data.</p><p>At its peak, it's believed the subject access request backlog had grown as high as 7,753.</p><p>The ICO acknowledged the difficulties faced by the MoJ, especially as pandemic restrictions limited affected its ability to process SARs. However, the "substantial number" of SARs that are out of time for compliance was "a cause of significant concern for the Commissioner," the ICO said in the <a href="https://ico.org.uk/media/action-weve-taken/enforcement-notices/4019412/the-minstry-of-justice-en-20220112.pdf">enforcement notice</a>.</p><p>It also added that "previous meetings and correspondence between the controller and commissioner have proven largely ineffective in reducing the number of outstanding SARs".</p><p>Failure to meet the demands of the enforcement notice will result in a fine of £17.5 million or 4% of its annual global turnover, whichever is higher. The MoJ has 28 days to appeal the notice.</p><p>"We take our responsibilities seriously and have set out an action plan to clear the backlog," an MoJ spokesperson told <em>IT Pro.</em>"</p><p>"The MoJ devotes significant resources to meeting these legal obligations, and we have hired extra staff to assist in clearing outstanding requests," they added. "The pandemic has had an unprecedented impact on our work, but we responded quickly and adapted ways of working to continue to provide a level of service to requestors.</p><p>"We have engaged in constructive dialogue with the ICO before and throughout the pandemic and have a clear action plan we have in place to clear the backlog."</p><h3 class="article-body__section" id="section-timeline-of-events"><span>Timeline of events</span></h3><p>The ICO originally became aware of a backlog at the MoJ on 7 January 2019, which resulted in conversations with the <a href="https://www.itpro.com/strategy/29856/data-controllers-responsibilities" data-original-url="https://www.itpro.com/strategy/29856/data-controllers-responsibilities">data controller</a> over the following year. This almost led to an enforcement notice being issued - a formal exercise of the Commissioner's powers for violations of <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection</a> law - which was ultimately delayed due to the pandemic.</p><p>According to the ICO, the pandemic "led to a shift in Commissioner's approach to regulatory action" and saw the investigation into the MoJ paused. New societal restrictions affected the MoJ's ability to respond to the backlog of SARs, the data controller told the ICO in an October 2020 update. Urgent cases were being prioritised, such as those affecting legal proceedings, police investigations, and immigration hearings.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="twFQWGnpSuXfswsCrh4NE4" name="twFQWGnpSuXfswsCrh4NE4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/twFQWGnpSuXfswsCrh4NE4.png" mos="https://cdn.mos.cms.futurecdn.net/twFQWGnpSuXfswsCrh4NE4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Modern governance: The how-to guide</strong></p><p class="fancy-box__body-text">Equipping organisations with the right tools for business resilience</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/it-governance/361792/modern-governance-the-how-to-guide" data-original-url="/policy-legislation/it-governance/361792/modern-governance-the-how-to-guide">FREE DOWNLOAD</a></p></div></div><p>The ICO said contact between it and the MoJ resumed in March 2021 and by April, it became aware that the MoJ was facing 5,956 outstanding SARs to which the MoJ had only partially responded. A total of 372 of these dated back as far as 2018.</p><p>Regular progress updates from the MoJ regarding how it was addressing the backlog were then requested by the ICO and by May 2021, the backlog had grown to 6,398. The backlog grew further to 7,753 by August 2021 after the MoJ said it predicted the resumption of a full SAR service by "summer/autumn 2021". It also said that of the near-8,000 outstanding cases, 25 received no response at all and around 960 predated the pandemic.</p><p>The MoJ promised to address the pre-pandemic cases first, setting itself a deadline of 31 May 2022, after which time it "will then move forward with plans to revisit the remaining 6,772 partial response cases in the timeliest way achievable".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European data regulators issued €1.1 billion in GDPR fines in 2021 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/362000/european-data-regulators-issued</link>
                                                                            <description>
                            <![CDATA[ The UK placed sixth on the GDPR fine tablewith its £20 million fine levied against British Airways ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jujZsbvkgVpZXP6WwmTnAX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N6UZUh94QX5sTJsEz8tek5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Jan 2022 11:23:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N6UZUh94QX5sTJsEz8tek5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Euro currency symbol displayed on a screen with European Union flag]]></media:description>                                                            <media:text><![CDATA[Euro currency symbol displayed on a screen with European Union flag]]></media:text>
                                <media:title type="plain"><![CDATA[Euro currency symbol displayed on a screen with European Union flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N6UZUh94QX5sTJsEz8tek5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>European data regulators issued €1.1 billion (£920 million) in GDPR fines last year, a 585% increase compared to 2020. </p><p>This is according to international law firm DLA Piper, which surveyed 27 EU member states, as well as the UK, Norway, Iceland, and Liechtenstein.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361848/grindr-fined-special-category-data" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/361848/grindr-fined-special-category-data">Grindr given €6.5 million GDPR fine for selling special category user data without consent</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/361652/ibm-unveils-world-first-machine-learning-training-method-for" data-original-url="/technology/machine-learning/361652/ibm-unveils-world-first-machine-learning-training-method-for">IBM unveils world-first machine learning training method for GDPR-compliance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361493/whatsapp-acquires-permission-to" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/361493/whatsapp-acquires-permission-to">WhatsApp secures permission to challenge €225 million GDPR fine</a></p></div></div><p>The survey identified an 8% increase in GDPR breach notifications from 2020’s average of 331 notifications per day to 356 in 2021.</p><p>Since 28 January 2021, there have been over 130,000 notified personal data breaches in total, with the Netherlands having the most breach notifications per 100,000 people respectively. On the other end of the spectrum, Croatia, the Czech Republic, and Greece reported the fewest number of breach notifications per capita.</p><p>Luxembourg issued the highest individual GDPR fine in 2021 with <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine">its €746 million fine levied against Amazon</a>. It followed by Ireland and <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine">its €225 million fine imposed against WhatsApp</a>, and France with its €50 million fine against Google. </p><p>The UK came in sixth place with the <a href="https://www.itpro.com/security/data-breaches/357452/british-airways-dodges-ps183-million-data-breach-fine" data-original-url="https://www.itpro.com/security/data-breaches/357452/british-airways-dodges-ps183-million-data-breach-fine">£20 million fine imposed on British Airways</a> for losing the financial and personal details of around 380,000 customers in a <a href="https://www.itpro.com/data-breaches/31854/british-airways-reveals-massive-data-breach-could-face-500m-fine-under-gdpr" data-original-url="https://www.itpro.com/data-breaches/31854/british-airways-reveals-massive-data-breach-could-face-500m-fine-under-gdpr">cyber attack in September 2018</a>. Since the implementation of GDPR, the UK has reported 40,026 personal data breach notifications, with 8,355 being reported in 2020 and 9,490 in 2021 – a 13.6% increase in one year.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/w8W2614bcHQ" allowfullscreen></iframe></div></div><p>DLA Piper’s survey also identified <em>Schrems II,</em> based on the 2020 ruling of <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism"><em>Data Protection Commissioner</em> v <em>Facebook Ireland Limited, Maximillian Schrems</em></a>, as the most common GDPR compliance challenge for organisations.</p><p>The case was originally brought by privacy activist Max Schrems, who claimed that Facebook was unjustified in its use of so-called ‘standard contractual clauses’ for the transfer of data between its EU headquarters and its US base in Silicon Valley. On 16 July 2020, the European Court of Justice decided that the data transfer mechanism known as <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> was unable to protect EU residents' data from extensive US surveillance mechanisms, making it no longer valid under GDPR.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iAVch4E74nXskoYH6rVd54" name="iAVch4E74nXskoYH6rVd54.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54.png" mos="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Modernise endpoint protection and leave your legacy challenges behind</strong></p><p class="fancy-box__body-text">The risk of keeping your legacy endpoint security tools</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/360946/modernise-endpoint-protection-and-leave-your-legacy-challenges" data-original-url="/security/endpoint-security/360946/modernise-endpoint-protection-and-leave-your-legacy-challenges">FREE DOWNLOAD</a></p></div></div><p>Commenting on the survey findings, Ross McKean, chair of the UK Data Protection and Security Group said that although the nearly sevenfold increase in fines may grab the headlines, it’s <em>Schrems II</em> that “has established itself as the top data protection compliance challenge for many organisations caught by GDPR.”</p><p>According to DLA Piper’s survey, the most common implications of the <em>Schrems II</em> judgment aren’t limited to fines and claims for compensation, but also service interruption caused by the suspension of data transfers, which McKean described as “much more damaging and costly”.</p><p>“The focus on transfers and the significant work required to achieve compliance inevitably means that organisations have less time, money and resources to focus on other privacy risks,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Europol ordered to delete huge cache of unlawfully stored data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/data-protection/361945/europol-ordered-to-delete-petabytes-data-innocent-individuals</link>
                                                                            <description>
                            <![CDATA[ The crime-fighting agency has failed to implement the necessary data protection measures it was told to make more than a year ago ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6tfW35fhSu9YDuuHKxwmEY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iJNKuUrtnEppaj2ojupLoE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Jan 2022 10:49:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iJNKuUrtnEppaj2ojupLoE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Photo of Europol&amp;#039;s headquarters]]></media:description>                                                            <media:text><![CDATA[Photo of Europol&amp;#039;s headquarters]]></media:text>
                                <media:title type="plain"><![CDATA[Photo of Europol&amp;#039;s headquarters]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iJNKuUrtnEppaj2ojupLoE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Europol has been accused of unlawfully storing, and ignoring requests to delete, large amounts of data on individuals with no established link to criminal activity.</p><p>The European Data Protection Supervisor (EDPS) has <a href="https://edps.europa.eu/data-protection/our-work/publications/other-documents/europol-order-and-faq_en">ordered</a> Europol to delete the data it has been storing, concluding a years-long inquiry into the crime-fighting agency's data collection habits.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/361523/europol-report-ddos-ransomware-gangs-evade-capture" data-original-url="/security/cyber-crime/361523/europol-report-ddos-ransomware-gangs-evade-capture">Europol reveals how ransomware gangs are evolving to evade capture</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/358450/europol-takes-down-dangerous-emotet-botnet" data-original-url="/security/malware/358450/europol-takes-down-dangerous-emotet-botnet">Europol takes down 'dangerous' Emotet botnet</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="/data-protection/28177/data-protection-policies-and-procedures">Data protection policies and procedures</a></p></div></div><p>The order follows the EDPS 'admonishment' of Europol more than a year ago in September 2020 when it was first found to be storing large volumes of data with no Data Subject Categorisation - a requirement stipulated by the Europol Regulation.</p><p>The EDPS said that while <a href="https://www.itpro.com/security/cyber-crime/361523/europol-report-ddos-ransomware-gangs-evade-capture" data-original-url="https://www.itpro.com/security/cyber-crime/361523/europol-report-ddos-ransomware-gangs-evade-capture">Europol</a> has complied with some requests and implemented "some" technical measures since then, it has not complied with other requests including failing to define an appropriate data retention period.</p><p>The measures introduced reduce, but do not remove, the possibility that individuals' fundamental rights could be put at risk by unlawful analysis of their data by Europol, or by the data being shared with other law enforcement agencies. As such, the data being stored does not ensure compliance with the Europol Regulation, the EDPS said. </p><p>It means Europol was keeping this data for longer than was necessary and violated the principles of data minimisation and storage limitation enshrined in the Europol Regulation.</p><p>Europol's bank of data reportedly contains <a href="https://www.itpro.com/business-intelligence/28173/what-is-big-data" data-original-url="https://www.itpro.com/business-intelligence/28173/what-is-big-data">at least four petabytes of data</a> on at least 250,000 individuals linked to terror or crime offences, accumulated from national law enforcement authorities over the past six years, according to <a href="https://www.theguardian.com/world/2022/jan/10/a-data-black-hole-europol-ordered-to-delete-vast-store-of-personal-data"><em>the Guardian</em></a>.</p><p>Privacy advocates have told <em>IT Pro</em> that Europol's hoarding of data is "hugely concerning" and have been exacerbated by the law enforcement agency's reluctance to delete the data after being told to do so a year ago. The amount of data that was reportedly being stored by Europol could even be likened to the NSA's mass surveillance revealed by Edward Snowden.</p><p>"Admittedly, sorting through 4 petabytes of data could not have been an easy task for Europol," said Hannah Hart, privacy expert at ProPrivacy. "Such a vast quantity of data, which is roughly a fifth of the US Library of Congress, is even tantamount to mass surveillance in the eyes of many a privacy advocate. The stockpiling of this information – as well as the secrecy of its existence – has led to chilling comparisons to America’s infamous NSA, which conducted widespread telephone surveillance before its exposure by Edward Snowden."</p><p>"Law enforcement bodies are given enhanced rights to collect and process personal data to perform their security functions," said Ed Hayes, partner at UK law firm TLT to <em>IT Pro</em>. "Citizens have a reasonable expectation that those organisations will be doing everything possible to ensure they comply with the law when exercising those extensive rights. When they fail to do so, it reduces trust, and that has knock-on effects.</p><p>“Law enforcement bodies are often at the forefront of deploying new technologies like AI and facial recognition," he added. "If they can’t be trusted to get the basics of data protection right – things like having proper data categorisation, storage and retention arrangements – it calls into question whether they should be trusted with deploying potentially far-reaching and intrusive new technologies.”</p><p>As Europol has failed to comply with requests, the EDPS will now exercise its corrective powers and impose a six-month retention period, and all datasets older than six months that have not undergone Data Subject Categorisation must be deleted. Europol has been given a 12-month grace period in which to comply with the EDPS' decision.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/2CKy9qJo1j3Evk9Ra5pZC4"></iframe><p>"Europol has dealt with several of the <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection</a> risks identified in the EDPS’ initial inquiry," said Wojciech Wiewiórowski, the EDPS. "However, there has been no significant progress to address the core concern that Europol continually stores personal data about individuals when it has not established that the processing complies with the limits laid down in the Europol Regulation.</p><p>"Such collection and processing of data may amount to a huge volume of information, the precise content of which is often unknown to Europol until the moment it is analysed and extracted - a process often lasting years."</p><p>The EDPS thinks that six months is enough time for Europol to extract all the critical data needed from the datasets and to provide any support to law enforcement authorities in EU member states.</p><p>Europol will also be required to submit reports to the EDPS every three months for the next 12 months updating him on the progress of its efforts to implement the necessary measures outlined in this week's decision.</p><h3 class="article-body__section" id="section-security-vs-privacy-concerns"><span>Security vs. Privacy concerns</span></h3><p>The news of Europol storing this large amount of data has led many to be concerned with the level of risk to individuals' rights but the EDPS decision also raises a debate around the balance between protecting an individual's right to privacy against the need to protect national security. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9TaVJkUXK2WrTiGqMtckqc" name="9TaVJkUXK2WrTiGqMtckqc.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/9TaVJkUXK2WrTiGqMtckqc.jpg" mos="https://cdn.mos.cms.futurecdn.net/9TaVJkUXK2WrTiGqMtckqc.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Freedom from manual data management</strong></p><p class="fancy-box__body-text">Build a data-driven future with Oracle</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/databases/361793/freedom-from-manual-data-management" data-original-url="/data-insights/databases/361793/freedom-from-manual-data-management">FREE DOWNLOAD</a></p></div></div><p>"This is a great example of the central dilemma of an open society – the need for privacy versus the need for security," said Edmund Probert, Commercial, IT Contracts and Intellectual Property Partner at international law firm Spencer West to <em>IT Pro</em>. "Clearly Europol, with which the UK has a co-operation agreement, has been trying to hold data for far too long in the view of the European Data Protection Supervisor. As a result, he has thrown all the toys out of the pram."</p><p>"Given the size of the databases, this amounted to the sort of mass surveillance the like of which we expect from dictatorships and totalitarian countries – not the EU. While the decision is couched in diplomatic terms, it is a damming report – and in simple terms, this is a ‘final warning’ with performance monitoring."</p><p>"Europe’s data protection regime relies on data controllers taking their legal obligations seriously, and that’s especially the case for public authorities operating in the law and order space," said Hayes of TLT. "Europol’s failure to comply with previous clear directions from the EDPS is so concerning precisely because it brings into question in what other ways it is ignoring the data protection law that should govern its actions."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Most UK businesses say data regulations are stifling AI innovation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence-ai/361871/most-uk-businesses-say-data-regulations-stifle-ai</link>
                                                                            <description>
                            <![CDATA[ Limited technological capabilities and poor access to data are preventing investment in AI ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pcXjBvhk66XwPVNfwJMifo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4WigUvrUj5RppqEeQTSkv8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Dec 2021 13:40:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4WigUvrUj5RppqEeQTSkv8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image showing data visualised as ocean waves to symbolise artificial intelligence]]></media:description>                                                            <media:text><![CDATA[Abstract image showing data visualised as ocean waves to symbolise artificial intelligence]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image showing data visualised as ocean waves to symbolise artificial intelligence]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4WigUvrUj5RppqEeQTSkv8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than two thirds (70%) of UK businesses have stated that they need more information to help them navigate the complex legal requirements surrounding data collection, use, and sharing across systems that use artificial intelligence (AI).</p><p>A <a href="https://www.gov.uk/government/news/new-research-reveals-the-most-pressing-opportunities-and-barriers-to-trustworthy-innovation-in-data-and-ai">new survey</a>, commissioned by the <a href="https://www.itpro.com/policy-legislation/32400/uk-gov-appoints-first-seats-for-centre-for-data-ethics-and-innovation" data-original-url="https://www.itpro.com/policy-legislation/32400/uk-gov-appoints-first-seats-for-centre-for-data-ethics-and-innovation">Centre for Data Ethics and Innovation (CDEI)</a>, asked 1,000 UK businesses about the key barriers to trustworthy innovation in data and AI.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358239/uk-ranked-second-for-gdpr-fines" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/358239/uk-ranked-second-for-gdpr-fines">UK ranked second for value of GDPR fines issued in 2020</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/354887/third-of-small-businesses-dont" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/354887/third-of-small-businesses-dont">Third of small businesses don’t feel GDPR applies to them</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/361784/uk-workers-are-least-afraid-of-being-replaced-by-ai" data-original-url="/technology/artificial-intelligence-ai/361784/uk-workers-are-least-afraid-of-being-replaced-by-ai">UK workers are least afraid of being replaced by AI</a></p></div></div><p>Nearly half of the surveyed businesses (43%) stated that limited technological capabilities are preventing them from investing in AI, while just under a quarter (23%) of respondents cited difficulty in accessing quality data.</p><p>Commenting on today’s findings, CDEI interim chair Edwina Dunn said that “data and AI can help tackle some of the greatest challenges of our time”, yet “in order to achieve this, we need to overcome barriers to innovation”, which include poor quality data as well as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/361691/uk-gov-launches-algorithmic-transparency-standard" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/361691/uk-gov-launches-algorithmic-transparency-standard">risks of algorithmic bias</a>.</p><p>“The CDEI is working in partnership with a range of organisations to help them overcome these barriers, mitigate risk and put high-level ethical principles - such as accountability and transparency - into practice. It’s practical work like this that will enable us to build greater public trust in how data and AI are used,” she added.</p><p>The UK’s minister for <a href="https://www.itpro.com/technology" data-original-url="https://www.itpro.com/technology">Technology</a>, Chris Philp MP, said that data and AI can assist the UK in its economic and social recovery “as we look to build back better”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="A7E5LkAp9fQtCkRAWiHBVZ" name="A7E5LkAp9fQtCkRAWiHBVZ.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/A7E5LkAp9fQtCkRAWiHBVZ.jpg" mos="https://cdn.mos.cms.futurecdn.net/A7E5LkAp9fQtCkRAWiHBVZ.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to manage AI risk</strong></p><p class="fancy-box__body-text">Recommendations from the Cyber Resilience Think Tank</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/361093/how-to-manage-ai-risk" data-original-url="/technology/artificial-intelligence-ai/361093/how-to-manage-ai-risk">FREE DOWNLOAD</a></p></div></div><p>“Understanding how we can best use technologies to address major shifts in labour markets and the ways that we work, deliver education or decarbonise our transport infrastructure, will be crucial to this mission,” he said, before adding that he looks forward to “working with organisations across the UK to address the barriers to innovation highlighted in the CDEI’s analysis, so that the UK can unlock the full potential of data and AI”.</p><p>Today’s findings are helping the CDEI and the Office for Artificial Intelligence in developing an upcoming AI Whitepaper that aims to assist businesses in ensuring that AI systems meet their regulatory obligations.</p><p>Last year, the CDEI found that a number of UK sectors may be <a href="https://www.itpro.com/technology/artificial-intelligence-ai/356122/significant-public-distrust-deterring-businesses-from" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/356122/significant-public-distrust-deterring-businesses-from">unwilling to experiment and engage in AI-based innovation</a> for <a href="https://www.itpro.com/technology/artificial-intelligence-ai/355130/why-transparency-is-key-to-promoting-trust-in" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/355130/why-transparency-is-key-to-promoting-trust-in">fear of sustaining reputation damage</a>, with CDEI chair Roger Taylor calling for more concerted government support and a clear national policy regarding the technology.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Grindr given €6.5 million GDPR fine for selling special category user data without consent ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361848/grindr-fined-special-category-data</link>
                                                                            <description>
                            <![CDATA[ The Norwegian DPA claims users' sexual orientations were exposed following the sale of data to third parties ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">onZ7bS1FWtDRt9Qhmh3erP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y36V378mviubRkE4AFwKjG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Dec 2021 13:31:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y36V378mviubRkE4AFwKjG-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Grindr app on a smartphone in front of a background of its logo]]></media:description>                                                            <media:text><![CDATA[The Grindr app on a smartphone in front of a background of its logo]]></media:text>
                                <media:title type="plain"><![CDATA[The Grindr app on a smartphone in front of a background of its logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y36V378mviubRkE4AFwKjG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Datatilsynet, the Norwegian Data Protection Authority (DPA), has fined location-based LGBTQ+ dating app Grindr €6.5 million (£5.4 million) for selling user data for advertising purposes without consent.</p><p>Considered the largest GDPR fine issued by the Nowegian authority to date, the penalty states Grindr unlawfully shared personal data of users with third parties for advertising and marketing purposes.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid" data-original-url="/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">GDPR fines: How high are they, and how can you avoid them?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go" data-original-url="/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go">GDPR fines: Where does the money go?</a></p></div></div><p>The fine was ultimately reduced from its initial sum of 100,000,000 NOK (£8.2 million) as a result of Grindr's co-operation with the Norwegian DPA and quick fixes to remediate its consent management platform.</p><p>Describing Grindr's infringements as "grave", <a href="http://www.datatilsynet.no/en/regulations-and-tools/regulations/avgjorelser-fra-datatilsynet/2021/gebyr-til-grindr">the authority said</a> that user GPS locations, IP addresses, advertising IDs, ages, and genders were included in the data shared with third parties. It also concluded that the fact users had been identified as Grindr account holders meant that sexual orienation data had been shared, which is <a href="https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/special-category-data">considered a special category under GDPR</a> and requires additional justification for processing.</p><p>"We consider that data revealing the fact that someone is a Grindr user strongly indicates that they belong to a sexual minority," said the Norwegian DPA. "Data concerning a person’s sexual orientation constitutes special category data that merit particular protection under the GDPR. As the consents Grindr collected were not valid, Grindr could not lawfully share such data.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=46975747&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>"While it not defined as special categories of personal data in itself, location data is sensitive and personal. The fact that Grindr has also shared this data unlawfully adds to the severity of the case."</p><p>The DPA also said Grindr users were forced into accepting the app's privacy policy in order to access its full set of features and were not asked specifically if they consented to their <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data</a> being shared with third parties for behavioural advertisement.</p><p>The fine is the largest ever issued by the Norwegian DPA, which said further orders may be issued to Grindr. The Norwegian Consumer Council, which originally filed the complaint against the company, has already claimed the dating app infringed additional provisions of GDPR and has asked the DPA to order Grindr to erase the illegally processed data.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QDksvAYJFwkcCugTbPvwS9" name="QDksvAYJFwkcCugTbPvwS9.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" mos="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Protecting every edge to make hackers’ jobs harder, not yours</strong></p><p class="fancy-box__body-text">How to support and secure hybrid architectures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours" data-original-url="/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours">FREE DOWNLOAD</a></p></div></div><p>Grindr has a three-week window in which it can launch an appeal to the fine, which may be extended depending on circumstances, the DPA said.</p><p>"We strongly disagree with Datatilsynet’s reasoning, which concerns historical consent practices from years ago, not our current consent practices or Privacy Policy," said Shane Wiley, chief privacy officer at Grindr, to <em>IT Pro</em>.</p><p>"Even though Datatilsynet has lowered the fine compared to their earlier letter, Datatilsynet relies on a series of flawed findings, introduces many untested legal perspectives, and the proposed fine is therefore still entirely out of proportion with those flawed findings.</p><p>"We’ve just received a copy of the letter from Datatilsynet and are analysing the document. The Company is considering its options including the right to appeal the findings to the Personvernnemnda (PVN - Appeal Board)," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The risks and strategies of using privacy as a business differentiator ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies</link>
                                                                            <description>
                            <![CDATA[ With privacy increasingly driving customer decisions, here’s how to make it a differentiator for your business ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aW2owdbuzAkzk2FiK1Vrg3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VEmLoUaMYNiDp3gtGJkRng-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Dec 2021 08:00:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VEmLoUaMYNiDp3gtGJkRng-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Faces in binary code to represent privacy]]></media:description>                                                            <media:text><![CDATA[Faces in binary code to represent privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Faces in binary code to represent privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VEmLoUaMYNiDp3gtGJkRng-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In a modern business landscape that can see data breaches and leaks devastate a firm’s reputation, privacy is more important than ever. As users become increasingly aware of their privacy, it’s not difficult to work out why tech giant Apple has placed the area at the heart of its <a href="https://www.youtube.com/watch?v=8w4qPUSG17Y" target="_blank">marketing strategy</a>.</p><p>The iPhone maker – which continues to make headlines with its <a href="https://www.itpro.com/security/privacy/358451/apples-block-on-activity-tracking-to-arrive-early-spring" target="_blank" data-original-url="https://www.itpro.com/security/privacy/358451/apples-block-on-activity-tracking-to-arrive-early-spring">App Tracking Transparency</a> feature that prevents firms such as Facebook from tracking iOS devices – calls privacy a “<a href="https://www.apple.com/uk/privacy" target="_blank">fundamental human right”</a>, and this is boosting its reputation among users. Apple’s privacy ethos stands in stark contrast to Facebook, which, after the <a href="https://www.itpro.com/policy-legislation/data-protection/357367/cambridge-analytica-project-was-ineffective-ico-claims" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/357367/cambridge-analytica-project-was-ineffective-ico-claims">Cambridge Analytica</a> scandal, <a href="https://www.itpro.com/business-operations/business-management/361100/facebook-algorithm-put-profit-before-public-safety" target="_blank" data-original-url="https://www.itpro.com/business-operations/business-management/361100/facebook-algorithm-put-profit-before-public-safety">whistle-blower allegations</a> and multiple breaches, is under continued pressure from its users. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war" data-original-url="/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war">Apple and Facebook's privacy dispute could lead to legal war</a></p></div></div><p>As the battle between Apple and Facebook <a href="https://www.itpro.com/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war" target="_blank" data-original-url="https://www.itpro.com/security/privacy/358470/apple-and-facebooks-privacy-dispute-could-lead-to-legal-war">rages on</a>, there’s no doubt privacy is becoming a key factor when people decide which service to use. As Apple and other privacy-aware companies have already discovered, embedding privacy into your business offers multiple benefits, such as driving customer acquisition and retention by fuelling trust. </p><p>Respecting privacy goes hand in hand with regulations such as the General Data Protection Regulation (GDPR) and the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018" target="_blank" data-original-url="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act 2018 (DPA)</a> in the UK. Under the regulation, firms are encouraged to be transparent and build privacy into their products and services from inception. In an age of fierce competition, standing out in a crowded market can be challenging. As privacy becomes increasingly central to all companies, therefore, how can you take advantage to differentiate?</p><h3 class="article-body__section" id="section-using-privacy-to-stand-out"><span>Using privacy to stand out </span></h3><p>High profile privacy infringements by big tech firms show just how easy it is to break trust, and how difficult it is to get it back. Trust is “hard to build, easy to break, and difficult to repair”, according to Bart Butler, CTO of ProtonMail, the privacy-centric email service provider. This, he adds, has helped fuel the growth of more privacy-focused solutions to take on those offered by <a href="https://www.itpro.com/data-insights/big-data/358795/pros-and-cons-of-breaking-up-big-tech" target="_blank" data-original-url="https://www.itpro.com/data-insights/big-data/358795/pros-and-cons-of-breaking-up-big-tech">big tech companies</a>. </p><p>Respecting user privacy doesn’t just drive customer loyalty; it helps avoid expensive regulatory headaches too. Indeed, regulation and the resulting fines and compensation claims can be extremely costly, says Will Richmond-Coggan, a data protection and privacy expert at law firm Freeths LLP. </p><p>Being clear which information is being collected and how it will be used is “essential”, he says, adding it’s equally important to be consistent. “This means data subjects don’t have a rude awakening after discovering their information is being used for a purpose that is very different to what they understood when they provided it.”</p><p>While technology makes it possible to collect data quickly and effectively, organisations should consider whether it’s correct to do so, says Isabel Ost, a UK data protection and privacy lawyer in the KPMG Law team. She describes how poor governance, <a href="https://www.itpro.com/hardware/361437/mitre-reveals-10-worst-hardware-security-weaknesses-in-2021" target="_blank" data-original-url="https://www.itpro.com/hardware/361437/mitre-reveals-10-worst-hardware-security-weaknesses-in-2021">security failings</a> and evidence of a deficient privacy culture “will turn away customers and reduce recommendations”. </p><p>In contrast, companies that incorporate <a href="https://www.itpro.com/security/32629/security-by-design-not-insecurity-by-default" target="_blank" data-original-url="https://www.itpro.com/security/32629/security-by-design-not-insecurity-by-default">privacy by design</a> in line with legal and ethical principles will stand out from their peers. Part of this means winding privacy into the customer journey, as well as the wider business strategy, Ost advises.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32629/security-by-design-not-insecurity-by-default" data-original-url="/security/32629/security-by-design-not-insecurity-by-default">Security by design, not insecurity by default</a></p></div></div><p>At the same time, firms should let customers know how much they care, says Gal Ringel, CEO and co-founder of Mine, a company focused on data privacy. Ringel advises businesses to “let customers know you care about their data and work hard to protect them”. </p><p>“If your target audience is worried about data privacy, invest further efforts in solving any related issues and making your achievements known.”</p><h3 class="article-body__section" id="section-regaining-trust-after-an-incident"><span>Regaining trust after an incident </span></h3><p>Companies get breached all the time, but how you handle incidents involving customer data can limit the long-term damage. In the event of a breach, firms must be media-ready, says Ost. As part of this, she says, companies need “a well-briefed communications team and a senior, credible, privacy-aware spokesperson”. </p><p>It’s vital that all staff are fully trained and able to anticipate questions, she adds, warning: “It only takes one poor or uninformed response – especially if a customer has a good understanding of their rights – to create a negative experience, as well as an investigation.”</p><p>It’s also important to respond quickly and decisively to incidents, says Richmond-Coggan. He points out that the UK’s <a href="https://ico.org.uk/for-organisations/report-a-breach" target="_blank">regulated notification period</a> to the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> following a data breach is “very short”, at 72 hours. “And,” he adds, “by the time that notification goes in, the business needs to know the extent of the issue and what they are going to do to put it right. </p><p>“Clear, coherent messaging to affected data subjects needs to follow promptly, ideally accompanied by an immediate suggestion of how the issue is going to be addressed, managed or eliminated.”</p><p>As part of this, firms need to be transparent and open about what went wrong. “Rebuilding trust starts by owning the mistake,” says Caroline Carruthers, CEO of data consultancy Carruthers and Jackson.</p><h3 class="article-body__section" id="section-data-protection-law-and-transparency"><span>Data protection law and transparency</span></h3><p>GDPR, and the UK’s interpretation of the regulation in the form of the DPA 2018, both <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">outline an ethos of transparency</a> regarding data collection and use. The regulations also focus on informed consent and privacy by design. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules" data-original-url="/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules">UK government to consider gutting GDPR rules</a></p></div></div><p>The main premise of the GDPR is to empower the end-user, says Simon Moffatt, founder of industry analyst firm the Cyber Hut. This includes “amplifying data protection by default, giving the end-user control over their data and allowing avenues for explicit consent capture and data use communication”. </p><p>UK data protection laws are very clear that people have a right to privacy, but it’s less obvious how businesses can differentiate themselves, says Carruthers. She likes the idea of a traffic light system for organisations “so you know how secure your data is and how compliant they are with the spirit of data protection laws”. </p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=46975747&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Of course, no such system is yet available, but experts agree that adhering to the regulation is a good start. It’s not a catch-all, however, with regulations also serving as a hindrance to a firm’s efforts to differentiate through privacy by design, Ost warns. In the case of the GDPR, any attempts to meet regulatory obligations must not be at the expense of a longer-term strategy that acknowledges privacy as a source of competitive advantage, she says.</p><p>“Consider how your organisation can meet the changing needs of customers and employees by building an ethical, privacy-aware culture and governance infrastructure, which puts the correct data at the right fingertips and consistently demonstrates transparency.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU reveals plans to protect whistleblowers from punishment in new legislation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/361643/eu-reveals-plans-to-protect-whistleblowers-from-punishment-in</link>
                                                                            <description>
                            <![CDATA[ Digital Markets Act aims to strengthen internal markets, prevent misuse of personal data, and impose massive fines on companies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u66ZAdy1d6bXbX9dBWt96Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6dWUQVtJGBtfJXbqgYdkxT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Nov 2021 11:42:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6dWUQVtJGBtfJXbqgYdkxT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of the European Commission building with EU flags flying in the foreground]]></media:description>                                                            <media:text><![CDATA[Image of the European Commission building with EU flags flying in the foreground]]></media:text>
                                <media:title type="plain"><![CDATA[Image of the European Commission building with EU flags flying in the foreground]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6dWUQVtJGBtfJXbqgYdkxT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU adopted a proposal on the Digital Markets Act (DMA) on Tuesday, part of which will protect whistleblowers from retaliation for alerting authorities to violations of new laws imposed on Big Tech companies.</p><p>The latest proposal on the DMA was accepted by an overwhelming majority of the Internal Market and Consumer Protection Committee and will introduce new rules for the <a href="https://www.itpro.com/data-insights/big-data/358795/pros-and-cons-of-breaking-up-big-tech" data-original-url="https://www.itpro.com/data-insights/big-data/358795/pros-and-cons-of-breaking-up-big-tech">biggest tech businesses</a>, setting out what they will and will not be allowed to do in the EU.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/358053/cma-proposes-digital-markets-unit-to-tackle-tech-giants" data-original-url="/business/policy-legislation/358053/cma-proposes-digital-markets-unit-to-tackle-tech-giants">CMA proposes 'Digital Markets Unit' to regulate tech giants</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359427/ico-devising-bespoke-uk-mechanism-for-global-data-sharing" data-original-url="/policy-legislation/data-protection/359427/ico-devising-bespoke-uk-mechanism-for-global-data-sharing">UK devising EU-alternative mechanism for global data sharing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other" data-original-url="/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other">GDPR and Brexit: How will one affect the other?</a></p></div></div><p>Part of the latest DMA proposal stipulates that Internal Market MEPs should ensure adequate protections are afforded to <a href="https://www.itpro.com/business/policy-legislation/361355/uk-gov-must-act-now-to-regulate-facebook-says-whistleblower" data-original-url="https://www.itpro.com/business/policy-legislation/361355/uk-gov-must-act-now-to-regulate-facebook-says-whistleblower">whistleblowers</a> at companies who fall under the DMA's remit and violate its rules.</p><p>Companies that will be bound by the DMA, should it be passed into law after consideration by the European Parliament, are known as 'gatekeepers'. A business qualifies as a gatekeeper if it operates in the European Economic Area (EEA), generates €8 billion (£6.7 billion) in annual turnover, and has a market capitalisation of at least €80 billion (£67 billion).</p><p>Gatekeepers will also have to operate a core platform in at least three EU countries and have at least 45 million end users, as well as more than 10,000 business users.</p><p>As part of the EU's so-called 'dos and don'ts', gatekeepers must "refrain from imposing unfair conditions on businesses and consumers". Lawmakers specifically identified data-driven profiling and targeted advertising as an area requiring change.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wYRY2NQiuWys3PgkS46wLB" name="wYRY2NQiuWys3PgkS46wLB.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/wYRY2NQiuWys3PgkS46wLB.png" mos="https://cdn.mos.cms.futurecdn.net/wYRY2NQiuWys3PgkS46wLB.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Content syndication isn't dead, but your data processes might be</strong></p><p class="fancy-box__body-text">It's a new (lead) generation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-processing/361546/content-syndication-isnt-dead-but-your-data-processes-might-be" data-original-url="/data-insights/data-processing/361546/content-syndication-isnt-dead-but-your-data-processes-might-be">FREE DOWNLOAD</a></p></div></div><p>In line with GDPR, gatekeepers will be punished for collecting personal data for their own commercial purposes or to deliver targeted advertisements to consumers unless users give "<a href="https://www.itpro.com/policy-legislation/data-protection/355570/swiping-and-scrolling-is-not-consent-edpb-says" data-original-url="https://www.itpro.com/policy-legislation/data-protection/355570/swiping-and-scrolling-is-not-consent-edpb-says">clear, explicit, and renewed informed consent</a>".</p><p>Crucially, collecting and using the personal data of minors to drive direct marketing or targeted advertising strategies will be entirely forbidden, regardless of whether they have given <a href="https://www.itpro.com/data-insights/data-management/358099/the-rise-of-consent-and-preference-management" data-original-url="https://www.itpro.com/data-insights/data-management/358099/the-rise-of-consent-and-preference-management">consent</a>.</p><p>Punishments for violating the rules as set out in the DMA, should they be adopted into law, will be in the form of fines of no less than 4% and no greater than 20% of the gatekeeper's global turnover.</p><p>“The EU stands for competition on the merits, but we do not want bigger companies getting bigger and bigger without getting any better and at the expense of consumers and the European economy," said Andreas Schwab, Rapporteur and German MEP for the European People's Party on Tuesday.</p><p>"Today, it is clear that competition rules alone cannot address all the problems we are facing with tech giants and their ability to set the rules by engaging in unfair business practices," he added. "The Digital Markets Act will rule out these practices, sending a strong signal to all consumers and businesses in the Single Market: rules are set by the co-legislators, not private companies!"</p><p>"With the Digital Markets Act, the EU is putting an end to the absolute market dominance of big online platforms in the EU," said Anna Cavazzini, Internal Market and Consumer Protection Committee chair and German MEP for Greens/EFA.</p><p>The DMA will also give new powers to the EU enabling it to effectively halt so-called 'killer acquisitions' initiated by gatekeepers. The European Commission will be able to restrict gatekeepers from making acquisitions that could damage the internal market and impose “structural or behavioural remedies” where gatekeepers have exhibited systematic non-compliance.</p><p>If the timescale across which GDPR was implemented in EU member states is anything to go by, the DMA will likely take a few years to be enacted into law, according to Usman Wahid, data, digital, and technology team lead at KPMG, and will require great effort on behalf gatekeepers to introduce.</p><p>"Complying with the proposed regulation will be a significant exercise for online platforms," he said. "The proposals will affect the business models, operating models, organisation and governance of most of the online platforms which are subject to the regulations.</p><p>"We believe online platforms should start their assessment by considering the structure of the proposed regulation and whether a precedent already exists within existing EU law.</p><p>Wahid added that the DMA has a similar legislative structure to existing competition laws and is "a good starting point with lessons learned applied to enhance the chances of success".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WhatsApp secures permission to challenge €225 million GDPR fine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361493/whatsapp-acquires-permission-to</link>
                                                                            <description>
                            <![CDATA[ The company has been granted the power to challenge Ireland’s fine over the way it shares user data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r25p4vyUH5pPN36RzMvFqb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8Z8noSoku2cTDxLzRGuy9Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Nov 2021 12:22:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8Z8noSoku2cTDxLzRGuy9Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person holding a smartphone with the WhatsApp logo displayed on screen]]></media:description>                                                            <media:text><![CDATA[A person holding a smartphone with the WhatsApp logo displayed on screen]]></media:text>
                                <media:title type="plain"><![CDATA[A person holding a smartphone with the WhatsApp logo displayed on screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8Z8noSoku2cTDxLzRGuy9Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/tag/whatsapp" target="_blank" data-original-url="https://www.itpro.com/search/whatsapp">WhatsApp</a> has secured permission in Ireland’s High Court to challenge the Data Protection Commission’s (DPC) decision to fine the company €225 million in August over its lack of transparency in the way it shares user data.</p><p>Justice Anthony Barr agreed to grant the <a href="https://www.itpro.com/tag/facebook" target="_blank" data-original-url="https://www.itpro.com/search/facebook">Facebook</a>-owned company permission to bring its challenge, and adjourned the matter to next month, as reported by <a href="https://www.thejournal.ie/whatsapp-ireland-data-commissioner-fine-5595637-Nov2021" target="_blank"><em>The Journal</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine">WhatsApp fined €225 million over obscure data sharing policies</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million">WhatsApp could face €50 million GDPR fine</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to">Irish data regulator fails to resolve 98% of big tech GDPR cases</a></p></div></div><p>WhatsApp is aiming to quash the DPC’s decision and seek declarations from the court, which include that certain parts of the 2018 Data Protection Act are invalid and unconstitutional and are incompatible with Ireland’s obligations under the European Convention on Human Rights.</p><p>The <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine">DPC issued WhatsApp with a penalty in August</a>, which was approved by the European Data Protection Board (EDPB), after a two-year investigation which found the company had been unclear in the way it processed and shared data with Facebook, as well as between WhatsApp and other Facebook-owned companies.</p><p>The investigation found that the company violated Article 14 of <a href="https://www.itpro.com/security/data-protection/gdpr" target="_blank" data-original-url="https://www.itpro.com/search/gdpr">GDPR</a>, which states that data controllers must provide data subjects with sufficient information about the way data is collected and processed.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TpQGJuV8JLJg48R7p8QdfN" name="TpQGJuV8JLJg48R7p8QdfN.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TpQGJuV8JLJg48R7p8QdfN.jpg" mos="https://cdn.mos.cms.futurecdn.net/TpQGJuV8JLJg48R7p8QdfN.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The top three IT pains of the new reality and how to solve them</strong></p><p class="fancy-box__body-text">Driving more resiliency with unified operations and service management</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/it-infrastructure/360224/the-top-three-it-pains-of-the-new-reality-and-how-to" data-original-url="/business-strategy/it-infrastructure/360224/the-top-three-it-pains-of-the-new-reality-and-how-to">FREE DOWNLOAD</a></p></div></div><p>The <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million">DPC’s draft findings from last December</a> outlined the fine should be between €30 million and €50 million before the EDPB issued a binding decision in July with a “clear instruction” for the watchdog to increase its provisional fine. The DPC raised it several times higher, and issued requirements for WhatsApp to take steps to improve its GDPR compliance as well.</p><p>In September, <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to">campaigners claimed that the DPC was failing to process a surging backlog of hundreds of GDPR</a> cases against big tech firms which was hindering pan-European data protection enforcement as a result. In the three years between May 2018 and May 2021 the data regulator only sent four draft decisions to the EPDB for examination and approval.</p><p>The report called the country “the big EU bottleneck” and said EU GDPR enforcement is “paralysed” due to Irenalnd’s failure to deliver draft decisions on cross-border cases.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Could the US CLOUD Act force UK channel companies to break GDPR? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/361221/could-the-us-cloud-act-force-uk-channel-companies-to-break-gdpr</link>
                                                                            <description>
                            <![CDATA[ The US has streamlined its processes for data requests from cloud services providers now embedded into almost every part of the UK economy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dX4EHj4s9QAPceRC6MQ4Bp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UXQm92a6enaRTk62tRkRkf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Nov 2021 08:00:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Fleur Doidge ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UXQm92a6enaRTk62tRkRkf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US flag outside Congress]]></media:description>                                                            <media:text><![CDATA[US flag outside Congress]]></media:text>
                                <media:title type="plain"><![CDATA[US flag outside Congress]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UXQm92a6enaRTk62tRkRkf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Although the channel won't likely have much to fear from corporate espionage, the <a href="https://www.justice.gov/dag/cloudact">US Clarifying Lawful Overseas Use of Data (CLOUD) Act</a> may yet increase costs and complexity, especially in the face of post-Brexit <a href="https://www.channelpro.co.uk/tags/gdpr">GDPR</a> reform.</p><p>Nigel Seddon, vice president of EMEA West at IT services management vendor Ivanti, says <a href="https://www.cloudpro.co.uk/collaboration/email/7410/cloud-act-brings-microsofts-us-data-privacy-court-spat-to-an-end">the act</a> will probably increase complexity in relationships and global supply chains already struggling with different data handling regimes from the EU to Singapore and beyond.</p><p>"You've got the dynamics of the UK now being separate from Europe, and here is yet another country, creating its own specific rules and regulations," Seddon points out. </p><p>Seddon notes that computer records are already increasing "tenfold" because electronic evidence is now required from online services providers in a majority of criminal investigations. Some <a href="https://journals.sagepub.com/doi/full/10.1177/2032284420919802">85% of European criminal investigations require such evidence</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to">Irish data regulator fails to resolve 98% of big tech GDPR cases</a></p></div></div><p>Additional data storage means extra cost, and the "number two expense" is the need for B2B services providers to learn how to handle related legislative queries with the correct levels of impartiality, authority and accuracy. </p><h2 id="another-edge-for-the-larger-players">Another edge for the larger players</h2><p>If you get the feeling this will disadvantage SMBs and sharpen the edge of large services providers with extensive legal and intellectual resources to devote to such tasks, Seddon agrees.</p><p>"More due diligence is going to be needed to understand the organisations and data you're working with to work out whether it's worth taking on a project – with potential implications to cost and brand if you mess up," Seddon notes.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="V54YJmE46MV9vmzvrWtaMA" name="V54YJmE46MV9vmzvrWtaMA.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/V54YJmE46MV9vmzvrWtaMA.jpg" mos="https://cdn.mos.cms.futurecdn.net/V54YJmE46MV9vmzvrWtaMA.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Reinvention starts with cloud migration of your data infrastructure</strong></p><p class="fancy-box__body-text">Explore why the most efficient way forward is data-driven</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-storage/360420/cloud-migration-of-your-data-infrastructure" data-original-url="/cloud/cloud-storage/360420/cloud-migration-of-your-data-infrastructure">FREE DOWNLOAD</a></p></div></div><p>The CLOUD Act was created under president Donald Trump in March 2018 to help US agencies chase down criminal activity by helping them request data held by service providers in other jurisdictions. </p><p>The UK indicated cooperation with this law by passing the Crime (Overseas SCA orders) Act in 2019 – but while under the EU's GDPR Act, <a href="https://www.linklaters.com/en/insights/blogs/digilinks/2019/september/us-cloud-act-and-gdpr-is-the-cloud-still-safe">it wasn't clear if UK providers would be subject to such requests</a>. </p><p>John Story, general counsel and chief data ethics officer at cloud platform provider Acoustic, notes the CLOUD Act <a href="https://www.itpro.com/cloud/360423/the-controversial-cloud-act" data-original-url="https://www.itpro.com/cloud/360423/the-controversial-cloud-act">conflicts with GDPR</a>, giving US law enforcement powers to request data stored by US companies on servers outside the US.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/360423/the-controversial-cloud-act" data-original-url="/cloud/360423/the-controversial-cloud-act">The controversial CLOUD Act</a></p></div></div><p>"This extra-territorial compulsion has raised concerns about the safety of information in the cloud and potential conflicts with EU and UK data laws, including GDPR," he says.</p><p>"Under US law, the service provider has to accept the request. But under European and UK regulations, there must be a lawful basis for processing that data."</p><h2 id="all-still-to-play-for-with-gdpr-reform">All still to play for with GDPR reform</h2><p>Michael Queenan, chief executive of cloud services brokerage Nephos Technologies, thinks nothing will change in the short term due to the CLOUD Act. </p><p>However, the UK can now diverge from GDPR, <a href="https://www.pinsentmasons.com/out-law/news/uk-data-protection-reform-planned">having announced in August that it will reform data protection law</a>.</p><p>"It might mean UK data needs to reside in the UK in the future. That would be a large change," Queenan says.</p><p>Christina Walker, global channel sales and programmes director at data erasure software vendor Blancco, says most of Blancco's UK channel have reported that they're <a href="https://www.gdpreu.org/the-regulation/key-concepts/data-controllers-and-processors">data managers only – not data owners</a> – and therefore don't expect "a tonne" of legal complexity.</p><p>"The CLOUD Act <a href="https://www.justice.gov/dag/page/file/1153466/download">was to create a more effective process</a>, instead of taking 10 months to get data that can help close a crime. And Google or those US cloud providers can and do reject requests," Walker points out.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR)</p></div></div><p>The UK's enabling Act is about protecting its citizens amid the continued evolution of the US cloud, streamlining a process to reject requests from the US government, Walker explains.</p><p>On the other hand, Fredrik Forslund, vice president of cloud and datacentre erasure solutions at Blancco and a director of the International Data Sanitisation Consortium (IDSC), says that the "jury is still out".</p><h2 id="real-world-ramifications">Real-world ramifications</h2><p>The CLOUD Act was initially about helping the US Federal Bureau of Investigation (FBI) carry out its duties and expectations more easily, but since then it has experienced mission creep. Bodies including the CIA and National Security Agency (NSA) may now also gain access, suggesting requests could go beyond crime-fighting into more political interests, Forslund suggests.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="V54YJmE46MV9vmzvrWtaMA" name="V54YJmE46MV9vmzvrWtaMA.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/V54YJmE46MV9vmzvrWtaMA.jpg" mos="https://cdn.mos.cms.futurecdn.net/V54YJmE46MV9vmzvrWtaMA.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Reinvention starts with cloud migration of your data infrastructure</strong></p><p class="fancy-box__body-text">Explore why the most efficient way forward is data-driven</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-storage/360420/cloud-migration-of-your-data-infrastructure" data-original-url="/cloud/cloud-storage/360420/cloud-migration-of-your-data-infrastructure">FREE DOWNLOAD</a></p></div></div><p>"In Europe, local and regional companies are using the CLOUD Act to promote their commercial alternatives to any US cloud service," he says. "They have a golden opportunity to promote a distinct difference as part of their commercial messaging."</p><p>US tech giants will naturally wish to comply with their national interests, but this won't be seen that way everywhere, he says. How will business partners in China, Iran or Russia feel about greater exposure to US legislation, for example? </p><p>Forslund also wonders whether UK public sector contracts might pull back from US cloud services for sensitivity reasons, as well as the expected rise in cost and complexity for IT providers.</p><p>"It can be really complicated to pull specific data out of these cloud architectures, and then being able to combine the technical aspect of it with the administrative aspect of the document. What you're looking for and how it has been approved, and that is a burden," says Forslund.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why Big Brother could be your friend ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/361216/why-big-brother-could-be-your-friend</link>
                                                                            <description>
                            <![CDATA[ As high street stores join the NICE Investigate Digital Evidence Management system, what does this mean for the wider business community? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ffcNuopL9YJJi4wr8bBd1k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ym6Mo77aKm58EHtNat5fEP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Oct 2021 07:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/QST9gbWQZLs5T4KfoM2StL.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ym6Mo77aKm58EHtNat5fEP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of several CCTV cameras honing in on individuals]]></media:description>                                                            <media:text><![CDATA[Graphic of several CCTV cameras honing in on individuals]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of several CCTV cameras honing in on individuals]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ym6Mo77aKm58EHtNat5fEP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A major obstacle that police forces often face is obtaining information invariably locked away in data silos, such as volumes of CCTV footage. Delivering high-quality policing requires detailed and focused information, and a new initiative aims to provide masses of new data for police officers to act on.</p><p>The Investigate Digital Evidence Management Software (DEMS) developed by <a href="https://www.nice.com/protecting/public-safety/nice-investigate">Nice</a> – an Israel-based company that specialises in data security and surveillance – automates evidence collection. It’s been adopted by the <a href="https://nbcc.police.uk">National Business Crime Centre (NBCC)</a>, a body created by the Home Office to improve relationships between businesses and law enforcement and improve intelligence gathering. NBCC hopes the police, armed with more CCTV data, can better protect businesses’ premises and their staff. Wider data sharing also raises concerns about privacy, and <a href="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state" target="_blank" data-original-url="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state">the expansion of the surveillance state</a>, especially given existing provisions set out in law.</p><h3 class="article-body__section" id="section-eyes-wide-shut"><span>Eyes wide shut</span></h3><p>Boots was among the first large enterprises to agree to supply DEMS with its CCTV data. “We have a large number of stores with both internal and external CCTV cameras for investigating all types of crimes and incidents,” says Iona Blake, Boots’ security and incident manager. “The addition of the Nice investigate technology allows Boots to engage in the right level of data sharing with local police forces. For us, it’s all about how can we get better at reporting crimes.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/361191/is-australia-becoming-a-surveillance-state" data-original-url="/security/privacy/361191/is-australia-becoming-a-surveillance-state">Is Australia becoming a surveillance state?</a></p></div></div><p>Alongside CCTV footage, the DEMS architecture <a href="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics" target="_blank" data-original-url="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics">can absorb other forms of digital content</a> and aggregate this to deliver case reports when they’re needed. These datasets can also be seen through what the developers call a Google-like search engine that uses <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws" target="_blank" data-original-url="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Microsoft Azure</a> as its hosting platform.</p><p>Although more businesses are expected to sign up for DEMS in the coming months, relinquishing CCTV footage wholesale may invoke controversy among customers, given the extent to which they <a href="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media" target="_blank" data-original-url="https://www.itpro.com/data-protection/34415/how-to-maintain-your-privacy-on-social-media">may feel their privacy is being violated</a>. The public would support the broader use of DEMS, however, if the appropriate protections are put in place, Tony Porter, CPO at Corsight AI and former Surveillance Camera Commissioner, tells <em>IT Pro</em>. </p><p>"Policies will need to be developed to ensure unnecessary data isn’t stored or transferred to law enforcement, which could potentially breach data processing principles,” he says. “Looking at this issue through a different prism, are we seriously saying the public is satisfied with the use of CCTV, provided its use is ineffective? As technology advances, perhaps we’re now seeing its intended value.”</p><h3 class="article-body__section" id="section-search-and-detect"><span>Search and detect</span></h3><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDWPShop8idtg5y5PK4Eu4" name="TDWPShop8idtg5y5PK4Eu4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TDWPShop8idtg5y5PK4Eu4.png" mos="https://cdn.mos.cms.futurecdn.net/TDWPShop8idtg5y5PK4Eu4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Hybrid cloud for video surveillance</strong></p><p class="fancy-box__body-text">What it is and why you'll want one</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/360218/hybrid-cloud-for-video-surveillance" data-original-url="/cloud/360218/hybrid-cloud-for-video-surveillance">FREE DOWNLOAD</a></p></div></div><p>The retail sector is highly susceptible to crime, with the latest British Retail Consortium (BRC) <a href="https://brc.org.uk/media/677737/brc-crime-survey-2021.pdf">Crime Survey</a> finding violence against staff rose from 424 incidents to 455 per day between April 2019 and March 2020. This was recorded alongside £935 million of losses due to theft. The fact that only 6% of violent incidents end in prosecution, too, is fuelling calls for greater access to CCTV footage. With the British Security Industry Association (BSIA) estimating ten million CCTV cameras operate across the UK, this source of information is, unsurprisingly, highly desired. Businesses, however, must reconcile the value in granting access to their footage with their obligation to comply with data protection regulations.</p><p>The BRC is clear, in its report, that any existing regulations shouldn’t pose a barrier to effective law enforcement. It also urges the Information Commissioner's Office (ICO) should ignore suggestions by the European Data Protection Board to limit the sharing of CCTV data. How CCTV footage is used can become highly contentious, however, as was shown by the case of <a href="https://www.itpro.com/policy-legislation/33680/police-in-the-dock-over-facial-recognition" data-original-url="https://www.itpro.com/policy-legislation/33680/police-in-the-dock-over-facial-recognition">Ed Bridges v South Wales Police (SWP)</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/357351/uk-mass-surveillance-regime-is-illegal-eu-court-declares" data-original-url="/security/privacy/357351/uk-mass-surveillance-regime-is-illegal-eu-court-declares">UK 'mass surveillance' regime is illegal, EU court declares</a></p></div></div><p>Bridges initially complained his image was taken using automated facial recognition (AFR) technology while he was shopping in 2017. The court sided with SWP, at first, but he escalated the case to the Court of Appeal last year, which took his side. The court ruled SWP never sought to establish whether the software <a href="https://www.itpro.com/technology/artificial-intelligence-ai/358223/why-diversity-is-key-to-a-successful-ai-strategy" target="_blank" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/358223/why-diversity-is-key-to-a-successful-ai-strategy">harboured underlying biases</a>. This case speaks volumes about how much care must be taken when capturing and sharing CCTV data, with businesses required to ensure they’re fully compliant with all regulatory requirements.</p><p>Jason Smith, chief commercial officer for Meeco, a platform that enables access control to data, tells <em>IT Pro</em> that public sentiment could become an issue if CCTV footage was shared more freely with law enforcement. “A lot of research around the world suggests we are all concerned about data privacy, but we don't have any agency,” he says. “The public sentiment may well be “I'm not happy...but what can I do about it?”. Ed Bridges wasn't very happy, but he needed the support of Liberty to bring a claim and take it to the Court of Appeal. I imagine most people aren't even aware of any rights they may have under GDPR.”</p><h3 class="article-body__section" id="section-avoiding-mission-creep"><span>Avoiding mission creep</span></h3><p>The more data systems like DEMS are fed, the more efficiently they operate. Linking thousands of CCTV cameras together would supply the system with vast ocenas of data. Systems like this, however, could be seen as the thin end of the wedge, according to co-founder of the Privacy Compliance Hub, Nigel Jones. </p><p>“The public and businesses need to think not about what this system is now, but what it may quickly become,” he tells <em>IT Pro</em>. “At present, it’s being positioned as a system to make it easier for the police to catch criminals such as shoplifters stealing razor blades and electric toothbrushes from Boots. It could, however, quite easily become a system that collates CCTV footage from security cameras in businesses, public places and from your neighbours' doorbells. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/public-sector/360569/robot-dogs-wont-save-policing-but-ai-just-might" data-original-url="/business-strategy/public-sector/360569/robot-dogs-wont-save-policing-but-ai-just-might">Robot dogs won't save policing – but AI just might</a></p></div></div><p>“Combine that with facial recognition and you have a system that can track me, you and all our children across any built-up area, which is accessible to a third-party software company we know little about, numerous police forces in the UK and overseas together with the governments in those countries, without any of us having consented to it, or really understood the consequences. That, to many, is an extremely frightening prospect.”</p><p>Nice’s executive vice president, Chris Wooten, dampens these fears, suggesting the need for businesses and police forces to work together is greater than ever. “The volume of crime is rising and getting digital evidence into the hands of police investigators can be a time-consuming, drawn-out, manual process,” he says. Officers, Wooton continues, may need to travel to sites across the country to collect evidence, which is time-consuming; systems that can streamline this process will help the police break through the log-jam and free up resources. Although systems like DEMS represent the inevitable evolution of <a href="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics" target="_blank" data-original-url="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics">data collection and analysis</a>, the critical component will be ensuring <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" target="_blank" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">strong safeguards are always in place</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: Can codes of conduct save GDPR?  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361244/podcast-transcript-can-codes-of</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8Y9zXG6m3mjKcQEssQ1knx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LUJbq87QaoySQagHhY8ZEL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Oct 2021 06:30:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LUJbq87QaoySQagHhY8ZEL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Podcast transcript: Can codes of conduct save GDPR? ]]></media:description>                                                            <media:text><![CDATA[Podcast transcript: Can codes of conduct save GDPR? ]]></media:text>
                                <media:title type="plain"><![CDATA[Podcast transcript: Can codes of conduct save GDPR? ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LUJbq87QaoySQagHhY8ZEL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode ‘Can codes of conduct save GDPR?’. To listen to the full episode,</em> <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361243/the-it-pro-podcast-can-codes-of" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361243/the-it-pro-podcast-can-codes-of"><em>click here</em></a><em>. We apologise for any errors. </em></p><h3 class="article-body__section" id="section-jane-mccallion"><span>Jane McCallion </span></h3><p>Hi, I'm Jane McCallion.</p><h3 class="article-body__section" id="section-adam-shepherd"><span>Adam Shepherd </span></h3><p>And I'm Adam Shepherd. </p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>And you're listening to the IT Pro Podcast where this week we're taking another look at GDPR.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>The DCMS is currently consulting on proposed changes to the UK's data protection regulation, with a stated goal of increasing clarity around how the rules should be applied, and making it easier for organisations to remain compliant without adding unnecessary burdens or stifling innovation.</p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>The proposed changes include scrapping the need for data protection impact assessments, and changing the rules around when businesses have to employ data protection officers, as well as significantly restructuring the Information Commissioner's Office.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>The government has said that it is planning to build on the existing GDPR and data protection acts rather than watering them down. But privacy campaigners have nonetheless expressed a certain degree of apprehension about what these changes could mean for the UK data protection landscape.</p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>There are some however, who feel that rather than the GDPR rules themselves, it's the way they've been interpreted that has caused problems. Today we're speaking to Chris Combemale, CEO of the Data and Marketing Association, who argues that instituting GDPR codes of conduct can enable the government to achieve its goals without rewriting the data protection rulebook. Chris, welcome to the show.</p><h3 class="article-body__section" id="section-chris-combemale"><span>Chris Combemale </span></h3><p>Thank you.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So Chris, just to kick off today's conversation, can you tell us a little bit about what the DMA does?</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>Sure; the Data and Marketing Association is the industry association that really represents the use of, of customer data, customer information, to find and keep customers. So really, that's an activity, a normal business activity that's existed throughout the centuries, that every business needs. And of course, in the data driven era, there's many more ways to maintain loyal, long term customer relationships. So we really, dating back to our original incarnation close to 100 years ago, as the British Direct Marketing Association, have always been focused on the issue of how do you properly collect and use data for customer relationships. And now really, that includes just about every channel, from traditional postal channels, telephone, email, text messaging, social media, an increasingly data driven TV, digital radio, and so on. So in that sense, when we approach legislation like GDPR, it's with the context of ensuring the frameworks are right, to protect the customer. But that's not in contrast to a business's objectives, which is to ensure that customers trust them, and want to do business with them over time.</p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>So how do you feel about the government's current proposals to amend the UK data protection legislation?</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>Yeah, I think the, the proposals are interesting in the sense that they build on the frameworks of GDPR, and also cover a little bit of amendment to the privacy and electronic communications regulation. So there are multiple legislations that that govern the use of, of data for for one to one communications. And I think what they've said and supporting the national data strategy, is the revisions they're looking to are to enable innovation and growth in business and clarify certain aspects of GDPR that may have become confused in implementation. And I think it's important in assessing the proposals to go back and remember that GDPR itself as written by the EU, with UK involvement in the drafting is a risk based legislation that balances different rights in different risks, but does it make one right overwhelmingly more important than another right. So if you start out from from what's written in recital four of GDPR. It says the processing of personal data should be designed to serve mankind. But the right to the protection of personal data is not an absolute right. It must be considered in relation to its function in society. And then it goes on to say this regulation respects all fundamental rights, including the right to conduct their business. So in and what we're really talking about is greater clarity, in that balance between essential data protection, that is important for people to trust the uses of data that's taking place, whether that be commercially or through public services, or in scientific research, or medical research, or in say, finding solutions to a global pandemic, like the COVID pandemic, none of it works unless people are confident that their data is being collected in a correct way, kept safe, and so on. But it's not a legislation that says the right to data protection is absolute, and trumps all other rights, or all of the things going on in society. And in that context, the government's proposals are completely consistent with both GDPR and privacy and electronic communications regulation, and in fact, build on those core principles and keep essentially most of the legislation as is but with some clarification, and some refinements, most of which we think are reasonably okay. </p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>Yeah. And this is actually something that I've heard around, that a lot of businesses, when they reacted to GDPR, they got very tunnel vision on the data protection, and the fact that people can ask for their information to be erased and all that, rather than also taking into account the legitimate interest side of things. And, and yeah, that seems to kind of play into what what you're saying.</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>Yeah, I think, you know, our members - who are probably the most experienced data driven marketers in the UK, both both established businesses that have been using data for communications for a long time, and newer businesses in the ecommerce and digital channel era - have have always, I think, understood how to get the balance right. And certainly, if you have customers that no longer want to do business with you, for whatever the reason, it's not actually efficient for that company to continue to communicate to you. It's not productive use of resources, and what companies are trying to do when they're collecting insight about their customers, and understanding what their customers buy, they're trying to find those customers that really do want to have a long term relationship and do want to buy from you frequently and do want to benefit from the things loyalty offers. And that's where companies want to invest their money, because that's what's profitable. So philosophically, then, there is no contradiction between what GDPR asks and what companies are trying to do. And actually, our members started from the perspective that they were very concerned about GDPR. And by the time implementation was done, mostly, you know, 70, 80% had concluded it had been good for their business, you know, because it required certain things, like knowing what data you hold on a customer and being able to look at it in the round and know why you held it, and what you were going to do with it. And many established companies would have had data in many different places, you know, from a promotional marketing database to a CRM database to a different and bringing it together. So that you knew what you held actually has a very good hygiene requirement and normal business, and really should have been done from the history of marketing.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, something that we heard a lot when GDPR first came into force was that it encouraged a lot of, a lot of companies and a lot of organisations to shake off some of the bad habits that they'd built up with regards to data in terms of just hoarding data that they didn't necessarily know if they needed, just because it might come in handy at some point. And I think that's a good habit to, to get out of, you know, with any kind of data driven operation, whether it's for marketing, or, you know, even if it's just like application data, and and that kind of stuff. So then moving on slightly. In your view, what are the main problems with how GDPR is implemented today?</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>Yeah, I think what we've seen GDPR presents six bases, for data processing, one of which is getting consent from your customer, there's probably you could use for the purpose of fulfilling a contract, you could use the basis of legitimate interest. There are six and they're equal. And what has happened in the implementation is through sort of muddled confusion, and I think, legal advice that's difficult, and the way data protection authorities across Europe have slightly confused things, there has been a tendency to believe or come to believe that consent is the only basis of processing customer information no matter what the purpose is, and what the communication that's going to resolve. Whereas in fact, recital 47, of GDPR says that direct marketing, in other words, the use of data to communicate to your customers, may be and is a legitimate interest. But many members have not wanted to do that. Now, having said that, there are safeguards, so sensitive personal data, requires consent. And there's other things that are specifically requiring of consent. But much communication could be done under legitimate interest, according to the way GDPR is written. So one of the proposals that the government is making, is to move some recitals into the main text to give them further, you know, because a recital is like an example. Whereas if you move it into the main text, it becomes factual. And they're proposing having a defined list of areas where legitimate interest might apply to give that clarity, so that you know that it really is one of six equal basis in the legislation. And I'll give you another example of the kind of clarification that's proposed that that we think is a good thing. Under privacy and electronic communications legislation. You can communicate to your existing customers by email, unless they unsubscribe, it's called the soft opt in. So you need consent for cold emails. But within your existing customers, you have the soft opt in, but the way the legislation is written through we think just an aberration is that that soft-in doesn't apply to charities and other type of organisations, where you have, again, very loyal customers. So someone who's passionate about saving dogs or saving birds, or disaster relief, or, or preventing harm from children, and donates regularly and volunteers their time to that organisation, there's no reason why that soft opt-in shouldn't extend to charity communications, and especially given the challenges they face financially in the current environment. And the fact that data driven marketing is the primary communication methods that not for profit use to raise money from from their donor base. So there's no reason that a loyal donor is different to a loyal customer of Tesco in terms of the depth of the relationship. And in fact, perhaps even more so because people are really passionate about the causes they support, and really want that relationship. So again, there's no reason why in PECR or GDPR, why a charity's donors should be considered different to a customer of Tesco or Sainsbury's or a bank or an insurance company. So what what the proposal the government has made does is it proposes to extend the soft opt in for email to definitively include charities and other types of organisations. And that just seems like sensible clarification and nothing to get overly excited about.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, cuz it's been three and a half years since GDPR came into force, and there's still a huge lack of, of clarity and lack of kind of awareness within business as to what they're allowed to do. And I think that's led a lot of businesses to err on the side of caution, particularly given the high potential fines that GDPR brought with it. I think that scared a lot of organisations into really playing it as safe as possible, often on the advice of legal departments and legal teams trying to minimise risk. But it's it has led to a lot of organisations being very conservative in their approach to data.</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>No, that's absolutely correct. And I think that's inherently the issue that some of the proposals the government is making is trying to clarify. And we believe those proposals are consistent with the intent of GDPR. And, you know, there's two things our members are concerned about. First, they have just gone through this major implementation change. So given the challenges of the pandemic, the challenges of Brexit, and other changes that are going through the structure of the UK, ideally, this change is in some ways good. Although the issue, you identify that and I think, absolutely, we need a bit of sense of clarity, so that businesses are not always taking the most risk free approach. You cannot innovate or create a modern economy, if you take a zero risk approach to everything. So there are problems in the way, in that overly conservative approach to GDPR because it prevents some activities that would be beneficial from taking place. So I think that's really important. And the second thing, our members, especially those who with international businesses, do not want to risk the recent data adequacy decision with the EU, because 40% of international data flows and exports, or thereabouts, go between the UK and the EU. And if that for whatever reason, became more restrictive, it would make it even more difficult to manage customers that are on the continent. And we all know the issues that already exist around the supply chain management, availability of labour and so on. So business just doesn't need another challenge between the UK and the EU in terms of doing business. But we don't think necessarily that a lot of the changes should pose that risk. So again, coming back to legitimate interest. Legitimate interest is an established legal basis for data processing going back decades in the EU. And the Dutch Data Protection Authority tried to limit its application and fine a company called Football TV for using legitimate interest as the basis which we think they were correct in doing so. The Dutch courts, not only strongly supported Football TV against the DPA but quoted European Court of Justice precedents, in particular, a precedent on a case called fashion ID, where the Advocate General Bobek said it was absolutely a legitimate interest to be able to advertise in the best possible way. And so European judicial precedents, support the clarifications that the government is making in terms of legitimate interest depending on how that final exhaustive list of when you can use legitimate interest. And so in that particular example, I don't see how that could risk adequacy, because what the government is proposing is completely consistent with the balancing of risks that GDPR expresses and with EU legal precedent. </p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>And I know that the DMA has suggested that Defining codes of practice for GDPR would be one way to make sure that people truly understand, or companies rather, truly understand what they should be doing. Does the government's proposals kind of fall in line with what you had in mind for that? Or are they something else?</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>Yeah, the government's proposals don't make changes necessarily to that side of things. So GDPR contains articles 40 and 41, which established codes of conduct for the interpretation of GDPR. So, clause 40, basically says, industry associations should be responsible for articulating how the legislation should be applied to their industry sector, and outlines specifically in the context of legitimate interest, that it should be the industry association that puts forward the codes of conduct, and then those are approved by the Data Protection Authority. So in the UK, that's the Information Commissioner's Office. And article 41 establishes independent monitoring bodies, also, which requires approval from the Information Commissioner's Office. So what GDPR and the way it was drafted in the EU and then transposed into UK law is a notion that industry experts who understand the processing that's taking place, that those experts who understand what the processing that's happening, would interpret how best to apply GDPR with the collaboration with the Information Commissioner's Office. And what that does is it establishes a form of co-regulation, where for companies who passed audit, under those codes of conduct would have complaints against them for that particular activity passed to the industry monitoring body to handle the complaint. So in essence, it becomes a whitelist of the good actors in an industry who have earned the right through passing the audit. And what it does for the ICO is it shifts a huge amount of low level complaints that are not causing harm from the ICO's investigative team to different industry monitoring bodies. But with escalation procedures, where if somebody goes off the rails, you can pass it back to the ICO. So we think that's really sensible. We've been working hard to get a code of conduct approved. There have been some approved in Europe, but UK is moving a little bit slowly. Now, what does create some confusion is the UK Data Protection Act in 2018, also establishes a requirement for the ICO to publish codes of practice, as distinct from codes of conduct. And one of the codes that they have to create as a code of practice is direct marketing, which overlaps with with our code of conduct. And it creates real confusion. So one of the proposals in chapter five of the government consultation that they're making is that when the ICO creates a code of practice, there should be a body of industry experts overseeing that code of practice. But that amounts to the same thing as the Industry Association, creating the code of conduct. So my view is we don't need both, we should just have the code of conduct. And there's no point to having a code of conduct and an industry monitoring body, and then a separate direct marketing code of practice, overseen by the same industry experts that arrives at the same conclusions. So I think there's a little bit of tension there, but the government is keeping articles 40 and 41 in their proposals, and they are adjusting the development of codes of practice so that they are more similar and recognise the industry expertise in the development of that code of practice. So we're kind of all on the same page. But it makes quite good sense for companies that treat their customers really, really well and have built trusted relationships and who have passed an audit for complaints that might arise through misunderstanding or error or something that goes a bit wrong one day, that that can be handled in a low level, informal way to resolve the issues rather than tying up investigative resources. </p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Yeah, absolutely. And one of the big complaints that's been levied against the ICO by kind of privacy campaigners in recent years, is the speed with which it processes investigations, you know, major investigations into things like the use of data by the big tech giants, Facebook, Google, etc. And, you know, investigations into like major serious data breaches, they take years to roll around and complete in for judgement and a fine if it's applicable to be issued. Do you think that offloading some of the more minor stuff from the ICO to this kind of self regulating industry body would free up more resources to help speed up those kind of major top level ICO investigations?</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>I think certainly it would. And I think the ICO's in favour of that whole part of the system based on the conversations we've had and would like to spend their time focused on the big issues, I think what you do have in an investigation is all kinds of opportunities to appeal and escalate beyond the ICO themselves.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>I mean, it's always going to take a certain length of time.</p><p>Chris </p><p>Yeah, I think those big companies can hire armies of the types of lawyers that can tie the ICO in knots so there's a tendency to be very cautious. But I would say, through the pandemic, maybe because they focused on helping the government, you know, with some of the apps that that tracked and traced and so on. But the Ico investigations are quite slow at the moment, it is a problem, especially for smaller businesses. And sometimes where in the process, the business is given the opportunity to respond to the complaint, our members find that the response is often not adequately taken into account in arriving. And so we have examples where the final notification is identical to the draft notification with not even a minor change based on the response of the company. So I do think there are issues there of timeliness and issues of fairness. But I also understand that, you know, like the big Cambridge Analytica Facebook case, they have to move with a certain amount of caution if they want to end at an outcome that's verifiable, because they are up against, you know, companies that will use every procedural issue to their benefit to try to get the issue to go away. So and I think that's why sometimes they've had to agree some reductions in some of the bigger fines they've they've issued and so on. It is an issue for sure. And I think some of the proposals in chapter five should make it speedier. And I think if lower level complaints that don't pose major harm, so I handle that will help the ICO focus on where the biggest risk to people exists.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>So you mentioned that one of the issues with GDPR's current implementation is that national data protection authorities often interpret the regulations differently. How would you ensure that the same thing doesn't happen with codes of conduct?</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>Okay, that's a really good question. Because, you know, when GDPR came into force, one of the main objectives of GDPR was turning the previous data protection legislation from 1998 from a directive, which gave each country the opportunity to have some flexibility, to a regulation, which theoretically means less flexibility nationally, although there are some carve outs, but in actual fact, every Data Protection Authority across the remaining 27 countries of the EU is interpreting and applying GDPR in a different way. And that is creating huge inconsistency and confusion. So one of the things we're doing, I chair FEDMA, which is the Federation of European DMAs, 21 DMAs from the 27 states. That's based in Brussels doing the lobbying, we are trying to create a network of national codes of conduct that harmonise the interpretation in the ways we think are consistent and I think, you know, if you have enough precedents from approved codes of conduct, whether they're an EU wide code of conduct that covers the 27 countries, or it's one in Austria and one in Poland. And they're covering similar topics and arrive at the same consensus, then you start to create that basis for business. But right now you have, you know, everything from Austria, who has approved a direct marketing code of conduct, specifically for postal third party data, and postal communications, which is consistent with what the government is proposing in their revisions to legislation. And then you have those Dutch, which I mentioned, who believe no business interest can be a legitimate interest. But as I said, the Dutch have lost in their own courts based on EU precedents. But the DPA is, and we say this all the time, the data protection authorities have to apply the legislation in the way it's written, they cannot apply the legislation with their own political biases in mind. You know, and the legislation is quite clear, in terms of the six bases and the balance and proportionate approach to different rights, because there are many rights always in every circumstance that need to be balanced with each other.</p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>So the government's consultation aims to increase innovation and growth, do you think that these current proposals will actually achieve this goal?</p><h3 class="article-body__section" id="section-chris"><span>Chris </span></h3><p>I think in terms of the areas that we are particularly focused on, as the data and Marketing Association, and in particular, some of the examples that I've given around clarification of legitimate interest, clarification of the soft opt in for email, in those areas that will absolutely help companies in going about the day to day business, of communicating with their customers, and at the same time, not pose any increased risk to those customers in terms of inappropriate behaviours, and so on. There is a whole other section that I haven't studied as much around changes to enable scientific research to be more easily conducted and, and data to be shared and reused. And I know there's applications that will make medical research a bit easier. So that we can get those insights about how be how diseases behave and find cures for those diseases. But I haven't really studied those but but my understanding is the intent of what's being proposed is to make it a little bit easier, because in the way that GDPR is written, anytime you're going to process data, you have to choose the basis, and then write a case for the basis. So if you're doing medical research, you have to go through the same experience. And so if certain things are clearly defined as being legitimate interests for medical research, and the changes and accountability that was put in place means that you don't have to, you know, what basis you're going to use, it's clear in law. And you don't have to write that little document that defines all your reasons why you're going to do it that way. And why you've made that choice. I think it does reduce an administrative burden, and makes it easier just to get on and do the important thing, which is designing new products, designing new cures, for diseases, and so on. But of course, that's balanced against, you know, the ethical approach to medical research as well. So if you're combining, you know, insight into how everybody has responded to a certain drug that's treating a certain disease and trying to find out why some people's body reacts in a different way, and so on. Obviously, it's quite sensitive. So again, there is a lot of work in the proposals around anonymization of data to ensure that you can conduct that research in a way that doesn't risk any individuals individual cases being put at harm. So I think the the intent is along the right lines. I think much of what we've seen is fairly pragmatic. I don't see much that should really get the privacy activists up in arms. Although often the privacy activists believe that the right to privacy takes priority over everything else. But I really don't think there's a huge amount that I think would pose harms to citizens and customers. In what's been proposed, it seems to us to be more in the form of clarification and pragmatic common sense.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>Well, I'm afraid that's all we have time for this week. But thank you once again to Chris Combemale from the Data and Marketing Association for joining us.</p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>You can find links to all of the topics we've spoken about today in the show notes and even more on our website, itpro.co.uk.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>You can also follow us on Twitter at @ITPro, as well as Facebook, LinkedIn, and YouTube.</p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>Don't forget to subscribe to the IT Pro Podcast wherever you find podcasts to never miss an episode. And if you're enjoying the show, leave us a rating and a review.</p><h3 class="article-body__section" id="section-adam"><span>Adam </span></h3><p>We'll be back next week with more from the world of IT but until then, goodbye.</p><h3 class="article-body__section" id="section-jane"><span>Jane </span></h3><p>Bye.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Can codes of conduct save GDPR? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361243/the-it-pro-podcast-can-codes-of</link>
                                                                            <description>
                            <![CDATA[ Why proposed revisions to data protection rules may not be necessary ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x5fmTpDqxduGNpPzaYdk5W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qUBTdsA8455ph9LCXeEPV9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Oct 2021 06:30:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qUBTdsA8455ph9LCXeEPV9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: Can codes of conduct save GDPR?]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: Can codes of conduct save GDPR?]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: Can codes of conduct save GDPR?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qUBTdsA8455ph9LCXeEPV9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ever since the UK left the EU, data protection has been a hot topic. On the one side government officials on one side argue that current rules are unnecessarily restrictive, while on the other privacy campaigners maintain that any changes to legislation could make it harder for organisations to do business with EU partners.</p><p>The solution to this conflict may lie in reinterpreting how we think about GDPR, rather than revising the regulations themselves. The UK’s Data and Marketing Association has suggested that GDPR codes of conduct could be a way to clarify the rules without having to water them down. We’re joined this week by DMA CEO Chris Combemale to discuss this idea, as well as the potential impact the government’s proposed changes to UK data protection laws could have on businesses.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=46975747&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights">Highlights</h2><p>“When GDPR came into force, one of the main objectives … was turning the previous data protection legislation from 1998 from a directive, which gave each country the opportunity to have some flexibility, to a regulation, which theoretically means less flexibility nationally ... but in actual fact, every Data Protection Authority across the remaining 27 countries of the EU is interpreting and applying GDPR in a different way. And that is creating huge inconsistency and confusion. So one of the things we're doing [is] trying to create a network of national codes of conduct that harmonise the interpretation in the ways we think are consistent.”</p><p>“If you have customers that no longer want to do business with you, for whatever the reason, it's not actually efficient for that company to continue to communicate with you. It's not a productive use of resources, and what companies are trying to do when they're collecting insight about their customers, and understanding what their customers buy, they're trying to find those customers that really do want to have a long term relationship and do want to buy from you frequently and do want to benefit from the things loyalty offers. And that's where companies want to invest their money, because that's what's profitable. So philosophically, then, there is no contradiction between what GDPR asks and what companies are trying to do.”</p><p><a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361244/podcast-transcript-can-codes-of" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/361244/podcast-transcript-can-codes-of"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li>What is GDPR? Everything you need to know, from requirements to fines</li><li><a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/359658/gdpr-turns-three-biggest-fines" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/359658/gdpr-turns-three-biggest-fines">GDPR turns three: The biggest fines so far</a></li><li><a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/355823/the-it-pro-podcast-happy-birthday" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/355823/the-it-pro-podcast-happy-birthday">The IT Pro Podcast: Happy birthday GDPR</a></li><li>DCMS lifts the lid on UK GDPR reforms, including ICO restructure</li><li><a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to">Irish data regulator fails to resolve 98% of big tech GDPR cases</a></li><li><a href="https://www.itpro.com/policy-legislation/data-protection/358520/the-it-pro-podcast-navigating-brexit-data-transfers" data-original-url="https://www.itpro.com/policy-legislation/data-protection/358520/the-it-pro-podcast-navigating-brexit-data-transfers">The IT Pro Podcast: Navigating Brexit data transfers</a></li><li><a href="https://www.itpro.com/data-insights/data-processing/361200/footballers-claim-performance-data-trading-violates-gdpr" data-original-url="https://www.itpro.com/data-insights/data-processing/361200/footballers-claim-performance-data-trading-violates-gdpr">Footballers seek compensation for "GDPR violating" performance data trading</a></li><li><a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/30107/get-gdpr-ready">Seven steps to GDPR compliance</a></li><li><a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine">Amazon faces £637 million fine over GDPR violations</a></li><li><a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">Data protection policies and procedures</a></li><li><a href="https://www.itpro.com/general-data-protection-regulation-gdpr/30967/nine-top-gdpr-tips-for-email-marketing-strategies" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/30967/nine-top-gdpr-tips-for-email-marketing-strategies">Nine top GDPR tips for email marketing strategies</a></li><li><a href="https://www.itpro.com/strategy/29856/data-controllers-responsibilities" data-original-url="https://www.itpro.com/strategy/29856/data-controllers-responsibilities">What are the responsibilities of a data controller?</a></li><li><a href="https://www.itpro.com/business-operations/marketing-comms/357981/delivering-data-driven-marketing" data-original-url="https://www.itpro.com/business-operations/marketing-comms/357981/delivering-data-driven-marketing">Three key steps to delivering data-driven marketing</a></li><li><a href="https://www.itpro.com/marketing-comms/34299/how-to-build-an-effective-marketing-strategy-with-the-cloud" data-original-url="https://www.itpro.com/marketing-comms/34299/how-to-build-an-effective-marketing-strategy-with-the-cloud">How to build an effective marketing strategy with the cloud</a></li><li><a href="https://www.itpro.com/data-insights/data-management/358099/the-rise-of-consent-and-preference-management" data-original-url="https://www.itpro.com/data-insights/data-management/358099/the-rise-of-consent-and-preference-management">The rise of consent and preference management</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://podcasts.apple.com/gb/podcast/the-itpro-podcast/id1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Footballers seek compensation for "GDPR violating" performance data trading ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-insights/data-processing/361200/footballers-claim-performance-data-trading-violates-gdpr</link>
                                                                            <description>
                            <![CDATA[ Letter threatening legal action against 17 firms that use trade player data claims the practice violates EU data protection law ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">htpRnqtzFJbNArtzzmgYWQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SxJ6Sdtb4kGxXtMT7mnknR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Oct 2021 11:34:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SxJ6Sdtb4kGxXtMT7mnknR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A player chasing the ball mid game]]></media:description>                                                            <media:text><![CDATA[A player chasing the ball mid game]]></media:text>
                                <media:title type="plain"><![CDATA[A player chasing the ball mid game]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SxJ6Sdtb4kGxXtMT7mnknR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hundreds of football players have threatened to take legal action against companies that use their performance data, claiming this practice is in violation of GDPR. </p><p>850 players, led by former Leyton Orient manager Russell Slade, have demanded compensation for the trading of their data over the past six years, according to the <a href="https://www.bbc.co.uk/news/uk-wales-58873132" target="_blank"><em>BBC</em></a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/354535/german-football-league-picks-aws-to-score-with-real-time-data" data-original-url="/technology/machine-learning/354535/german-football-league-picks-aws-to-score-with-real-time-data">German football league picks AWS to score with real-time data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/blockchain/31494/no-football-isnt-coming-home-but-it-appears-blockchain-is" data-original-url="/blockchain/31494/no-football-isnt-coming-home-but-it-appears-blockchain-is">No, football isn't coming home... but it appears blockchain is</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/356950/it-pro-live-how-pro-football-focus-became-the-nfls-secret" data-original-url="/business-strategy/data-insights/356950/it-pro-live-how-pro-football-focus-became-the-nfls-secret">IT Pro Live: How Pro Football Focus became the NFL's secret weapon</a></p></div></div><p>The data is a mixture of statistics, such as goals-per-game and physical information like a player's height, all of which is being harvested and used by 17 unnamed data collection, betting and entertainment firms, according to letters sent by Slade and the players. </p><p>Slade has previously expressed concern around the collection of performance data, and his legal team said the fact players do not receive payment for the unlicensed use of their data is actually in violation of GDPR. This could fall under Article 4 of the legislation where "personal data" refers to a range of identifiable information, such as physical attributes, location data or physiological information.</p><p>Although the letter has been sent to an initial 17 firms, Slade's Global Sports Data and Technology Group has actually highlighted more than 150 companies it believes have misused this type of data. If legal action is taken and the group is successful, it could herald sweeping changes for a multi-billion pound industry.</p><p>Slade's work here seems mostly for the benefit of lower league players - those outside of the lucrative Premier League - with the practice potentially affecting both the men's and women's game.</p><p>"It's incredible where it's used," Slade said to <em>the BBC</em>. "On one player, and I'm not talking about a Premier League player or even a Championship player, there were some 7,000 pieces of information on one individual player at a lower league football club.</p><p>"There are companies that are taking that data and processing that data without the individual consent of that player. A big part of our journey has been looking at that ecosystem and plotting out where that data starts, who are processing it, where it finishes and that's a real global thing. It's making football - and all sports - aware of the implications and what needs to change."</p><p>Regardless of any legal action, footballers should invest in cyber security insurance with additional layers of data protection, according to Niamh Muldoon, global data protection officer at OneLogin.</p><p>"In reality, no footballer should be operating without it," Muldoon told <em>IT Pro</em>. "Along with employing a personal cyber security/data protection advisor who will alert them of the latest threats while they keep focused on playing football. This will help protect their data, as well as digital identity from misuse or abuse. </p><p>"A core component of this is having cyber security and data protection terms outlined in all contracts that their agent puts in front of them, allowing them to see transparently how their data is being collected, protected and used. This will aid them in making informed risk-based decisions when entering into contractual agreements."</p><p>This case raises interesting questions over what is personal data and to what extent can the individual protect it, according to Frank Jennings, a lawyer who specialises in cloud and GDPR-related cases. </p><p>"When a player in an organised club scores (or doesn't score), that becomes a statistic and is logged in the annals of the club and, for the more prominent clubs and players, is often reported as news," Jennings explained to <em>IT Pro</em>. "The fact a goal was scored is not of itself personal data, but it is when attributed to the player who scored. Organised clubs are usually played in front of fans and usually anyone can watch a match when they buy a ticket. Just because that personal data is in the public domain doesn't mean that GDPR doesn't apply. But player consent is not the only basis on which data may be processed. It may be possible to rely upon another ground such as legitimate interest or the exception of public interest. Players can usually prevent unauthorised exploitation of their image.</p><p>"We await to see whether they can protect statistical information too," Jennings added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IBM signs CaixaBank in cloud services deal  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/360885/ibm-signs-caixabank-in-cloud-services-deal</link>
                                                                            <description>
                            <![CDATA[ The Spanish banking giant will use IBM Cloud for Financial Services to run key software applications ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rmmqd7r1SUKKEMWDKY4Qps</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UYicf7fzU7xSF2TBGw4ehE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Sep 2021 07:22:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UYicf7fzU7xSF2TBGw4ehE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A glass building with the IBM logo displayed on the window]]></media:description>                                                            <media:text><![CDATA[A glass building with the IBM logo displayed on the window]]></media:text>
                                <media:title type="plain"><![CDATA[A glass building with the IBM logo displayed on the window]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UYicf7fzU7xSF2TBGw4ehE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IBM expanded its presence in the European financial services market this week by inking a cloud services agreement with Spanish banking giant CaixaBank. </p><p>The company signed a multi-year agreement with CaixaBank to run financial software in its cloud infrastructure. Under the deal, the bank will use IBM Cloud for Financial Services to run key software applications while complying with the EU's GDPR data protection rules. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/360807/ibm-e1080-server-hybrid-cloud-official" data-original-url="/cloud/hybrid-cloud/360807/ibm-e1080-server-hybrid-cloud-official">IBM unveils next-gen Power10 server for hybrid cloud</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359012/cna-insurance-firm-suffers-extensive-network-disruption-amid-cyber" data-original-url="/security/ransomware/359012/cna-insurance-firm-suffers-extensive-network-disruption-amid-cyber">CNA Financial suffers extensive network disruption following cyber attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/high-performance-computing-hpc/360650/ibm-telum-ai-chip-fraud-detection-official" data-original-url="/server-storage/high-performance-computing-hpc/360650/ibm-telum-ai-chip-fraud-detection-official">IBM unveils on-chip AI accelerator for fraud detection</a></p></div></div><p><a href="https://www.itpro.com/cloud/public-cloud/359140/ibms-public-cloud-for-banking-is-not-generally-available" data-original-url="https://www.itpro.com/cloud/public-cloud/359140/ibms-public-cloud-for-banking-is-not-generally-available">Launched in April</a>, IBM Cloud for Financial Services enables financial institutions to host their software and services in the cloud while complying with regional regulations. It features a framework for financial services that includes a range of applications from IBM and third-party integrated software vendors. </p><p>As part of the service, CaixaBank will use IBM's data <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a> capabilities. The IT vendor's Cloud Hyper Protect Crypto Services encrypt financial services companies' data while allowing them to keep and manage their own security keys. This means that IBM is unable to decrypt the bank's data. </p><p>The CaixaBank deal coincides with the launch of IBM's Spanish multi-zone region (MZR). MZRs feature separate computing facilities connected by low-latency links that offer fail-over continuity. The Spanish zone will offer better regional coverage and address data sovereignty needs. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DfPkXvU2kswi3wVfaLtMcK" name="DfPkXvU2kswi3wVfaLtMcK.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/DfPkXvU2kswi3wVfaLtMcK.jpg" mos="https://cdn.mos.cms.futurecdn.net/DfPkXvU2kswi3wVfaLtMcK.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ of IBM Spectrum Virtualize</strong></p><p class="fancy-box__body-text">Cost savings and business benefits enabled by storage built with IBMSpectrum Virtualize</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/server-storage/360179/the-total-economic-impacttm-of-ibm-spectrum-virtualize" data-original-url="/infrastructure/server-storage/360179/the-total-economic-impacttm-of-ibm-spectrum-virtualize">FREE DOWNLOAD</a></p></div></div><p>Other features of the cloud service include compliance monitoring through the IBM Cloud Security and Compliance Center, and the use of isolated computing facilities and network segments, which heightens the privacy level for sensitive financial services workloads. IBM Cloud for Financial Services offers dedicated servers for financial software and can isolate traffic within availability zones. </p><p><a href="https://www.businessinsider.com/largest-banks-europe-list">Listed</a> as the 25th largest bank in Europe, CaixaBank is a ten-year old lender headquartered in Valencia. This year, the company completed the acquisition of rival Bankia for €4.3bn, making it the largest bank in Spain. </p><p>IBM has been focusing more heavily on its cloud business over the last few years, leading to a <a href="https://www.itpro.com/cloud/hybrid-cloud/359528/can-ibm-buy-its-way-to-cloud-success" data-original-url="https://www.itpro.com/cloud/hybrid-cloud/359528/can-ibm-buy-its-way-to-cloud-success">growth in this area</a> against a backdrop of falling overall revenues. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Irish data regulator fails to resolve 98% of big tech GDPR cases ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360859/irish-data-regulator-yet-to</link>
                                                                            <description>
                            <![CDATA[ Campaigners accuse the Irish DPC of being the ‘bottleneck’ for GDPR enforcement with 160 unresolved complaints ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4FH6KPYGoe3UioKoB7Emk3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SwugEXnXZd7Xf6vAnDuC5P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Sep 2021 10:07:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SwugEXnXZd7Xf6vAnDuC5P-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google, Amazon, Facebook and Apple apps on a smartphone display]]></media:description>                                                            <media:text><![CDATA[Google, Amazon, Facebook and Apple apps on a smartphone display]]></media:text>
                                <media:title type="plain"><![CDATA[Google, Amazon, Facebook and Apple apps on a smartphone display]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SwugEXnXZd7Xf6vAnDuC5P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Irish Data Protection Commission (DPC) is failing to process a surging backlog of hundreds of GDPR cases against big tech firms and is hindering pan-European data protection enforcement as a result, campaigners claim.</p><p>As of May 2021, the Irish DPC was the lead supervisory authority for 164 such cases of pan-European significance, <a href="https://www.iccl.ie/wp-content/uploads/2021/09/Europes-enforcement-paralysis-2021-ICCL-report-on-GDPR-enforcement.pdf" target="_blank">according to research by the Irish Council of Civil Liberties (ICCL)</a>, but 98% of these cases remained unresolved. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go" data-original-url="/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go">GDPR fines: Where does the money go?</a> DCMS lifts the lid on UK GDPR reforms, including ICO restructure <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine">WhatsApp fined €225 million over obscure data sharing policies</a></p></div></div><p>In the three years between May 2018, when GDPR came into force, and May 2021, the data watchdog has only sent four draft decisions to the European Data Protection Board (EDPB) for examination and approval.</p><p>“Ireland is the big EU bottleneck,” the report states. “No other GDPR enforcer in the EU can intervene if the Irish DPC asserts its lead role in cases against big tech firms headquartered in Ireland. As a result, EU GDPR enforcement against big tech is paralysed by Ireland’s failure to deliver draft decisions on cross-border cases.”</p><p>The Irish DPC, however, has categorically rejected the findings of the report, suggesting the statistics aren't accurate, and that it's just invested in the capabilities to handle a greater caseload.</p><p>“The DPC is on record calling for a proper peer review of statistics across the EU, however statistics included in this report are inaccurate," deputy commissioner, Graham Doyle, told <em>IT Pro</em>. </p><p>"The DPC has received more than 1,200 cross-border complaints from other Data Protection Authorities (DPAs) since the introduction of the GDPR in May 2018 with over 600 of these resolved.</p><p>"In terms of technical resources, no DPA will have the in-house tech skills to do everything. As the DPC informed the ICCL last week, we have just completed an extensive procurement exercise and we now have a framework worth over €2 million over the next few years, with five companies from which we can draw down state of the art, niche tech knowledge going forward.”</p><p>The Irish DPC is the most significant data protection authority in Europe because many major tech companies are based in Ireland due to favourable tax conditions. Ireland is home to the likes of Apple, Google and Facebook, as well Microsoft, eBay, Dropbox, and a dozen other major household names.</p><p>In practice, this means 21% of all complaints referred between regulators have been referred to the Irish DPC. Ireland, alongside Spain, Germany, the Netherlands, France, Sweden and Luxembourg, handle 72% of all complaints referred between DPAs. </p><p>When cross-border GDPR complaints arise concerning any Irish-based company, the Irish DPC is nominated as the lead supervisory authority by default to lead the investigation under the ‘one-stop shop’ principle. </p><p>Investigators are then expected to produce draft decisions, which are referred to the EDPB and fellow data protection authorities for approval, before a final decision is submitted. For example, in January the Irish DPC <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million">submitted a draft decision regarding a €50 fine against WhatsApp</a>. After intervention by fellow European regulators, and the EDPB, the Irish DPC <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine">increased the fine to €225 million</a>. </p><p>Campaigners have, in the past, criticised the Irish DPC for being slow to process a rising backlog of cases. <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/354842/irish-data-regulator-racks-up" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/354842/irish-data-regulator-racks-up">The organisation's own figures</a> showed that, in 2019, complaints rose by 75% even though no fines were collected. </p><p>The commissioner, Helen Dixon, said in February 2020 that the regulator was trying to lay a solid foundation for enforcement in light of the DPC’s increased prominence since GDPR was introduced. This included raising the staff count to cope with the demands of 2020 and beyond. </p><p>The ICCL, however, found the Irish DPC has been chronically underfunded for years, and, despite now being the fifth best-funded regulator, doesn’t have the structural capacity or staffing levels to cope with this demand.</p><p>However, this is an issue that's present more broadly across Europe, too. The UK’s <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a>, which hasn’t been examined in this report due to Brexit, is the largest regulator in Europe but only employs 13 people in its cyber investigations team.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DfPkXvU2kswi3wVfaLtMcK" name="DfPkXvU2kswi3wVfaLtMcK.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/DfPkXvU2kswi3wVfaLtMcK.jpg" mos="https://cdn.mos.cms.futurecdn.net/DfPkXvU2kswi3wVfaLtMcK.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ of IBM Spectrum Virtualize</strong></p><p class="fancy-box__body-text">Cost savings and business benefits enabled by storage built with IBMSpectrum Virtualize</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/server-storage/360179/the-total-economic-impacttm-of-ibm-spectrum-virtualize" data-original-url="/infrastructure/server-storage/360179/the-total-economic-impacttm-of-ibm-spectrum-virtualize">FREE DOWNLOAD</a></p></div></div><p>On the other hand, the report praised Spain’s regulator for its output, having submitted 41 draft decisions to the EDPB for cross-border cases as of May 2021. This is despite enjoying a smaller budget than the Irish DPC's, and a smaller staff count.</p><p>Senior fellow at ICCL, Johnny Ryan, who was previously chief policy and industry relations officer at Brave, co-authored the report and <a href="https://www.iccl.ie/wp-content/uploads/2021/09/Letter-to-European-Commission-Commissioner-Reynders.pdf" target="_blank">wrote a letter addressed to the EU commissioner for justice, Didier Reynders</a>. </p><p>In this letter, he called for the European Commission to monitor GDPR enforcement across the continent much better, and to take actions against regulators that are effectively undermining the data protection regime.</p><p>“ICCL believes that the costs of failing to properly apply the GDPR will be severe,” Ryan wrote. “The fanfare surrounding the GDPR was such that the EU’s global influence will wane if it is allowed to fail. </p><p>“Consumers will suffer too, because innovative startups and venerable news publishers will be unable to compete because of Big Tech’s entrenched internal data free-for-alls. The worst cost will be that continuing data misuse will tyrannise citizens, and debase politics. Therefore, we urge you to intervene.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ICO under fire over plans to urge G7 to tackle cookie pop-ups  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/information-commissioner/360791/ico-under-fire-g7-cookie-plans</link>
                                                                            <description>
                            <![CDATA[ The Open Rights Group says the data regulator should "follow its own conclusions and enforce the law" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gKjtHn42Q9EJvMeuQf3QtH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7G9PJGnjCj6Q3RyuZMqEne-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Sep 2021 09:36:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7G9PJGnjCj6Q3RyuZMqEne-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A website pop up for &amp;#039;cookies&amp;#039;]]></media:description>                                                            <media:text><![CDATA[A website pop up for &amp;#039;cookies&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[A website pop up for &amp;#039;cookies&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7G9PJGnjCj6Q3RyuZMqEne-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico#:~:text=The%20Information%20Commissioner's%20Office%20(ICO)%20is%20the%20UK's%20data%20protection,Data%20Protection%20Regulation%20(GDPR).">Information Commissioner</a> Elizabeth Denham is set to ask data regulators from G7 countries to join forces against online cookie pop-ups.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358637/what-are-supercookies" data-original-url="/security/privacy/358637/what-are-supercookies">What are supercookies?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">What is the Information Commissioner’s Office (ICO)?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/33850/ico-admits-its-own-cookie-policy-is-non-compliant-with" data-original-url="/general-data-protection-regulation-gdpr/33850/ico-admits-its-own-cookie-policy-is-non-compliant-with">ICO admits its own cookie policy is non-compliant with GDPR</a></p></div></div><p>Denham will meet with her counterparts on Tuesday, with each country set to raise a technology problem they believe can be solved with close collaboration. However, privacy experts feel the ICO could be doing more to tackle the cookie problem itself. </p><p>Cookie pop-ups are seen as an annoying obstacle by most internet users, but privacy advocates and regulators feel there is something more nefarious about them. They suggest they can be used to 'trick' users into accepting privacy invasions rather than reading through a long list of settings for each website they visit. </p><p>"There are nearly two billion websites out there taking account of the world's privacy preferences," Denham said. "No single country can tackle this issue alone. That is why I am calling on my G7 colleagues to use our convening power. Together we can engage with technology firms and standards organisations to develop a coordinated approach to this challenge."</p><p>The ICO added that it envisions a future where web browsers, applications and device settings allow people to set lasting privacy preferences of their choosing, "rather than having to do that through pop-ups every time they visit a website." </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ffna7TmpqYrgTZpXMRi9u6" name="ffna7TmpqYrgTZpXMRi9u6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" mos="https://cdn.mos.cms.futurecdn.net/ffna7TmpqYrgTZpXMRi9u6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Forrester Wave: Top security analytics platforms</strong></p><p class="fancy-box__body-text">The 11 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms" data-original-url="/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms">FREE DOWNLOAD</a></p></div></div><p>The call to tackle cookie pop-ups has backing from many in the tech industry, but there are questions being asked of the ICO and the UK government about its own enforcement of the "<a href="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law" target="_blank" data-original-url="https://www.itpro.com/data-insights/30421/what-exactly-is-the-cookie-law">unlawful</a>" data collection practices of <a href="https://www.itpro.com/security/privacy/358637/what-are-supercookies" target="_blank" data-original-url="https://www.itpro.com/security/privacy/358637/what-are-supercookies">cookie</a> banners. </p><p>Johnny Ryan, the chief policy officer for the privacy-focused browser Brave, suggested the ICO's plan was "daft" because the government could have fixed the cookie problem "before Brexit". He has previously pointed out that it is already illegal under GDPR and that the ICO just needs to do more enforcing itself. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1435128019488739329"></a></p></blockquote><div class="see-more__filter"></div></div><p>Jim Killock, the executive director of the Open Rights Group, also suggested the ICO should be doing more. He said that Denham's own reports have stated that most cookie banners and the data collection behind them are unlawful.</p><p>"If the ICO wants to sort out cookie banners then it should follow its own conclusions and enforce the law," Killock said. "We have waited for over two years now for the ICO to deal with this, and now they are asking the G7 to do their job for them. That is simply outrageous. We fully support their call for automated signals, but in the meantime they should enforce the law, which is their job."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WhatsApp fined €225 million over obscure data sharing policies ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360754/whatsapp-225m-fine</link>
                                                                            <description>
                            <![CDATA[ This finalised penalty is almost five times larger than the draft fine the Irish data regulator issued in December 2020 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t5G716jG6sAtn3MRR6pVmr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dFTB22UBkUWKAbv6whMk5a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Sep 2021 12:22:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dFTB22UBkUWKAbv6whMk5a-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Privacy settings on WhatsApp which uses end-to-end encryption]]></media:description>                                                            <media:text><![CDATA[Privacy settings on WhatsApp which uses end-to-end encryption]]></media:text>
                                <media:title type="plain"><![CDATA[Privacy settings on WhatsApp which uses end-to-end encryption]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dFTB22UBkUWKAbv6whMk5a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WhatsApp has been hit with a €225 million (approximately £193 million) GDPR fine for a lack of transparency in the way the service shares user data.</p><p>The penalty, which has been issued by the Irish Data Protection Commission (DPC) and approved by the European Data Protection Board (EDPB), is several times <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million">higher than the €50 million (roughly £43 million) draft fine</a> the Irish data regulator issued in December last year.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/358352/whatsapp-delay-privacy-update" data-original-url="/security/privacy/358352/whatsapp-delay-privacy-update">WhatsApp delays controversial privacy update for businesses</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/354842/irish-data-regulator-racks-up" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/354842/irish-data-regulator-racks-up">Irish data regulator racks up GDPR cases against Big Tech</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine">Amazon faces £637 million fine over GDPR violations</a></p></div></div><p>Following a two-year investigation, WhatsApp was found to have been unclear about the way it had processed and <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/359503/german-regulator-bans-facebook" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/359503/german-regulator-bans-facebook">shared data with Facebook</a>, as well as between WhatsApp and other Facebook-owned companies.</p><p>Specifically, the investigation found that WhatsApp violated Article 14 of GDPR, which states that data controllers must provide data subjects with sufficient information about the way data is collected and processed.</p><p>The provisional €50 million fine, issued under the one-stop-shop principle, was submitted to the Irish regulator's European counterparts for approval once it was issued. Ireland’s data watchdog was chosen as the lead supervisory authority because WhatsApp is headquartered in the country.</p><p>After eight of its counterparts raised a dispute, the EDPB issued a binding decision in July with a “clear instruction” for the Irish DPC to increase its provisional fine.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="V54YJmE46MV9vmzvrWtaMA" name="V54YJmE46MV9vmzvrWtaMA.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/V54YJmE46MV9vmzvrWtaMA.jpg" mos="https://cdn.mos.cms.futurecdn.net/V54YJmE46MV9vmzvrWtaMA.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Reinvention starts with cloud migration of your data infrastructure</strong></p><p class="fancy-box__body-text">Explore why the most efficient way forward is data-driven</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-storage/360420/cloud-migration-of-your-data-infrastructure" data-original-url="/cloud/cloud-storage/360420/cloud-migration-of-your-data-infrastructure">FREE DOWNLOAD</a></p></div></div><p>The regulator subsequently raised the level of its draft fine several times higher, alongside issuing requirements for WhatsApp to take steps to improve its GDPR compliance.</p><p>A summary published by the EDPB found the GDPR Article 14 infringements were “very serious in nature” and “severe in gravity”, with these violations amounting “to a high degree of negligence”.</p><p>WhatsApp has branded the fine “entirely disproportionate”, and claims it will appeal the penalty.</p><p>“We have worked to ensure the information we provide is transparent and comprehensive and will continue to do so," a WhatsApp spokesperson said. "We disagree with the decision today regarding the transparency we provided to people in 2018 and the penalties are entirely disproportionate. We will appeal this decision." </p><p>This fine is likely to be the first of many the regulator will issue against Facebook and its subsidiaries, with the regulator <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/354842/irish-data-regulator-racks-up" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/354842/irish-data-regulator-racks-up">currently working through a backlog of cases</a> against big tech firms. The regulator is also investigating <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/33111/facebook-is-subject-to-10-major-gdpr-investigations" target="_blank" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/33111/facebook-is-subject-to-10-major-gdpr-investigations">more than 10 complaints against Facebook-owned companies</a> alone.</p><p>This is the biggest GDPR fine issued to date, although it might soon be dwarfed if a <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine">provisional €746 million (approximately £637 million) fine</a> issued by Luxembourg’s regulator against Amazon is finalised.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT Pro News In Review: Nvidia-Arm deal in doubt, UK's post-Brexit data strategy, and massive data leak hits Microsoft Power Apps ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/mergers-and-acquisitions/360702/t-pro-news-in-review-27-august</link>
                                                                            <description>
                            <![CDATA[ Catch up on the biggest headlines of the week in just two minutes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pYeGtwfH9e5oanVoghHQwM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cLfGCR4BgRdfQb4EUfJGJP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 27 Aug 2021 10:38:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cLfGCR4BgRdfQb4EUfJGJP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT Pro News In Review: Nvidia-Arm deal in doubt, UK&amp;#039;s post-Brexit data strategy, and Microsoft Power Apps suite leaks 38 million records]]></media:description>                                                            <media:text><![CDATA[IT Pro News In Review: Nvidia-Arm deal in doubt, UK&amp;#039;s post-Brexit data strategy, and Microsoft Power Apps suite leaks 38 million records]]></media:text>
                                <media:title type="plain"><![CDATA[IT Pro News In Review: Nvidia-Arm deal in doubt, UK&amp;#039;s post-Brexit data strategy, and Microsoft Power Apps suite leaks 38 million records]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cLfGCR4BgRdfQb4EUfJGJP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/sLnm5Z-yn_o" allowfullscreen></iframe></div></div><p>Welcome to IT Pro's News in Review, a weekly bite-sized bulletin of the top tech stories of the week, for the week ending 27 August, 2021.</p><p>This week: </p><ul><li><a href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/360654/nvidia-arm-deal-in-danger-as-cma-raises-serious" data-original-url="https://www.itpro.com/business-strategy/mergers-and-acquisitions/360654/nvidia-arm-deal-in-danger-as-cma-raises-serious">Nvidia-ARM deal in danger as CMA raises ‘serious’ competition concerns</a></li><li><a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360694/uk-post-brexit-data-reform" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360694/uk-post-brexit-data-reform">UK reveals post-Brexit data reforms alongside flurry of international agreements</a></li><li><a href="https://www.itpro.com/security/data-breaches/360673/microsoft-power-apps-misconfiguration-exposes-38-million-records" data-original-url="https://www.itpro.com/security/data-breaches/360673/microsoft-power-apps-misconfiguration-exposes-38-million-records">Microsoft Power Apps misconfiguration exposes 38 million records</a></li></ul><p>You can find more videos like this in our video library and even more on <a href="https://www.youtube.com/user/itpro" rel="noopener" target="_blank">our YouTube channel</a>. Let us know what you think of this week's video – you can also find us on <a href="https://www.facebook.com/ITProUK" rel="noopener" target="_blank">Facebook</a>, <a href="https://www.linkedin.com/company/itpro-uk" rel="noopener" target="_blank">LinkedIn</a>, and <a href="https://twitter.com/ITPro" rel="noopener" target="_blank">Twitter</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK reveals post-Brexit data reforms alongside flurry of international agreements ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360694/uk-post-brexit-data-reform</link>
                                                                            <description>
                            <![CDATA[ The US, Australia, and South Korea are among the countries the government is prioritising for multi-billion-pound adequacy agreements ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4rZkxH4ex5jR8XRnf4XyDt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aHGnf9an8DunZKjZD94bug-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Aug 2021 09:35:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aHGnf9an8DunZKjZD94bug-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digitised globe with yellow beams spreading from the UK to the rest of the world]]></media:description>                                                            <media:text><![CDATA[A digitised globe with yellow beams spreading from the UK to the rest of the world]]></media:text>
                                <media:title type="plain"><![CDATA[A digitised globe with yellow beams spreading from the UK to the rest of the world]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aHGnf9an8DunZKjZD94bug-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK appears to be distancing itself from the EU’s GDPR with the announcement of plans to rewrite domestic data protection laws while pursuing lucrative data adequacy agreements with countries around the world.</p><p>The government has revealed a package of measures that will see it “move quickly and creatively” to strike adequacy agreements with a range of nations worth more than £11 billion in untapped trade. These will be subject to assessments to ensure high <a href="https://www.itpro.com/data-protection/28020/data-protection-principles" target="_blank" data-original-url="https://www.itpro.com/data-protection/28020/data-protection-principles">data protection standards</a>, according to the Department for Digital, Culture, Media and Sport (DCMS).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules" data-original-url="/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules">UK government to consider gutting GDPR rules</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other" data-original-url="/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other">GDPR and Brexit: How will one affect the other?</a></p></div></div><p>The first territories the government will negotiate with are the US, Australia, South Korea, Singapore, the Dubai International Finance Centre, and Columbia. These agreements will be followed by negotiations with India, Brazil, Indonesia, and Kenya. The UK currently recognises the data regimes of 42 countries as being adequate with its own.</p><p>The government has also <a href="https://www.itpro.com/policy-legislation/information-commissioner/360352/new-zealand-privacy-commissioner-tipped-for-uks" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/information-commissioner/360352/new-zealand-privacy-commissioner-tipped-for-uks">identified New Zealand’s privacy commissioner John Edwards</a> as its preferred candidate to replace Elizabeth Denham as the UK’s Information Commissioner, with a revised remit prioritising innovation over enforcing privacy rights.</p><p>“Now that we have left the EU I’m determined to seize the opportunity by developing a world-leading data policy that will deliver a Brexit dividend for individuals and businesses across the UK,” said DCMS secretary Oliver Dowden.</p><p>“That means seeking exciting new international data partnerships with some of the world's fastest growing economies, for the benefit of British firms and British customers alike.”</p><p>At the heart of this package of measures are plans to reform domestic data laws so they’re “based on common sense, not box-ticking”, Dowden added. This is the most explicit signal yet that the <a href="https://www.itpro.com/policy-legislation/data-protection/358874/uk-seeks-divergence-from-gdpr-to-fuel-growth" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/358874/uk-seeks-divergence-from-gdpr-to-fuel-growth">UK will distance itself from GDPR</a>, with the government suggesting the current regime is antagonistic towards innovation.</p><p>The government has previously signalled that it’s keen on scrapping GDPR rules, with prime minister Boris Johnson <a href="https://www.itpro.com/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359915/government-to-consider-gutting-gdpr-rules">commissioning a task force earlier this year to examine the UK’s data protection regime</a>.</p><p>This panel, comprising three right-wing Conservative MPs, blasted GDPR as being “prescriptive and inflexible” and recommended replacing the current regime with a new framework for data protection.</p><p>Government officials have also suggested that the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" target="_blank" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> focuses too heavily on privacy rights and data protection, and <a href="https://www.itpro.com/policy-legislation/information-commissioner/358823/next-information-commissioner-will-correct" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/information-commissioner/358823/next-information-commissioner-will-correct">not enough on innovation</a>. This is considered an ‘imbalance’ that needs addressing, with the government looking to John Edwards’ appointment as a chance to reform the role of the data protection watchdog.</p><p>In the coming weeks, the government will launch a consultation on how to change domestic data protection laws so it can “break down barriers” and speed up innovation, give businesses greater license to use data, and improve public services.</p><p>How exactly this data protection regime will be structured, and how vastly it might differ from GDPR, isn't clear. However, briefing national newspapers in advance of this announcement, officials said it would <a href="https://www.telegraph.co.uk/politics/2021/08/25/web-cookie-requests-red-tape-scrapped-post-brexit-data-revolution" target="_blank">lead to the end of web cookie requests</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QgCrBscxnvy55NTaMiScJC" name="QgCrBscxnvy55NTaMiScJC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QgCrBscxnvy55NTaMiScJC.png" mos="https://cdn.mos.cms.futurecdn.net/QgCrBscxnvy55NTaMiScJC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building a winning data strategy</strong></p><p class="fancy-box__body-text">Get serious about data and data science</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-management/360419/building-a-winning-data-strategy" data-original-url="/data-insights/data-management/360419/building-a-winning-data-strategy">FREE DOWNLOAD</a></p></div></div><p>“This set of ambitious announcements is welcome," said director of markets with techUK, Matthew Evans. "Data is a foundational asset for modern societies, creating accessible and trusted routes for businesses, civil society and researchers to access data from around the world will help drive innovation and create better digital services.</p><p>“However, these new routes must be trusted and command the confidence of the public. TechUK, therefore, welcomes the technical assessment criteria and commitment to high privacy standards laid out by the Government. Both of these will be vital to maintaining access to existing data flows, such as from the EU as well as opening up global opportunities."</p><p>European officials are expected to follow these developments closely given the UK was <a href="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/data-protection/360025/brexit-data-to-continue-to-flow-freely-between-uk-and-eu">only awarded a data adequacy agreement with the EU in June</a>. This indicates that the EU considers the UK’s data protection laws are harmonised with its own, which paved the way for data flows to continue post-Brexit without the need for businesses to pursue individual alternative mechanisms, such as standard contractual clauses (SCCs).</p><p>Any changes to UK data protection laws, however, might threaten the status of this agreement in future, with the agreement subject to being reviewed every four years while also being susceptible to legal challenge at any time.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zoom is no longer compatible with GDPR, Hamburg data watchdog claims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360625/zoom-incompatible-with-gdpr</link>
                                                                            <description>
                            <![CDATA[ Regulator claims city officials are using a "legally highly problematic system" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o4NNuCpLcZpL2E2sv1KBrn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ktKXC2YoUx6J7bNNgh7muK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Aug 2021 10:55:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ktKXC2YoUx6J7bNNgh7muK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom&amp;#039;s white camera on blue background logo]]></media:description>                                                            <media:text><![CDATA[Zoom&amp;#039;s white camera on blue background logo]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom&amp;#039;s white camera on blue background logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ktKXC2YoUx6J7bNNgh7muK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A German data protection commissioner has officially warned Hamburg's Senate Chancellery to avoid using <a href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now" target="_blank" data-original-url="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now">Zoom</a> as it is no longer compatible with GDPR.</p><p>Hamburg's acting Commissioner for Data Protection and Freedom of Information, Ulrich Kühn, said in a press release that the on-demand version of the video conferencing platform does not meet the legislation's criteria when it comes to data transfers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against" data-original-url="/general-data-protection-regulation-gdpr/31201/schrems-strikes-again-filing-gdpr-complaints-against">Schrems strikes again, filing GDPR complaints against Facebook and Google</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now" data-original-url="/software/355486/zoom-review-are-we-alone-now">Zoom review: Are we alone now?</a></p></div></div><p>He cites the European Court of Justice's (CJEU) <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism" data-original-url="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism">Schrems II decision</a><a href="https://www.itpro.com/security/privacy/359128/google-accused-of-illegally-tracking-android-users-with-advertising-codes" target="_blank" data-original-url="https://www.itpro.com/security/privacy/359128/google-accused-of-illegally-tracking-android-users-with-advertising-codes">,</a> announced in July 2020, which invalidated the EU-US data transfer mechanism known as <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield" data-original-url="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">Privacy Shield</a> and required alternative mechanisms to be more rigorous.</p><p>"All employees have access to a tried and tested video conference tool that is unproblematic with regard to third-country transmission," Kühn wrote. "As the central service provider, Dataport also provides additional video conference systems in its own data centres. These are used successfully in other countries [sic] such as Schleswig-Holstein. It is therefore incomprehensible why the Senate Chancellery insists on an additional and legally highly problematic system."</p><p>The issue appears to relate to a dispute over the way Zoom has used standard contractual clauses (SCCs) to justify its data transfers. On it's <a href="https://zoom.us/gdpr" target="_blank">website</a>, Zoom says its services feature "an explicit consent mechanism for EU users" on its platform and that the firm has implemented "zero-load" cookies for users whose <a href="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address" target="_blank" data-original-url="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address">IP address</a> show they are visiting the site from an EU member state. Specifically, the firm states: "we ensure that the transfer is governed by the European Commission's standard contractual clauses (SCC)".</p><p>However, following the Schrems II decision in July 2020, companies are now required to perform additional steps to justify their use of SCCs, including performing additional risk assessments - something that Zoom appears not to have done.</p><p>Neil Brown, the director of virtual English law firm decoded.legal, told <a href="https://www.theregister.com/2021/08/17/zoom_incompatible_with_gdpr_hamburg_warning" target="_blank"><em>The Register</em></a> that the press release was "somewhat oblique" but suggested that the Hamburg Data Protection Authority considers that Zoom does not ensure a level of protection for personal data which is "essentially equivalent" to that afforded by the GDPR.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZExAov8zyEmxT8mafdUAuP" name="ZExAov8zyEmxT8mafdUAuP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" mos="https://cdn.mos.cms.futurecdn.net/ZExAov8zyEmxT8mafdUAuP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The technology of trust</strong></p><p class="fancy-box__body-text">How to protect your most valuable commodity</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/359630/the-technology-of-trust" data-original-url="/marketing-comms/customer-experience-cx/359630/the-technology-of-trust">FREE DOWNLOAD</a></p></div></div><p>"Many businesses used to address the international transfers aspect of the GDPR by incorporating the model contract clauses/SCCs into their contracts with organisations in non-adequate jurisdictions," Brown told <em>The Register</em>. "In Schrems II, the CJEU said that these were not, in themselves, sufficient, and that a transferring controller must do a comprehensive risk assessment, and put appropriate additional measures in place to ensure 'essentially equivalent' protection.</p><p>"And that came as a shock to a lot of people, since it rather suggested that the model clauses were not fit for purpose. And, lo and behold, there is a new European set, which is a heck of a lot more complicated."</p><p>In a statement, Zoom said it was proud to work with the City of Hamburg and many other leading German organisations, businesses and education institutions.</p><p>"The privacy and security of our users are top priorities for Zoom, and we take seriously the trust our users place in us," the firm said. "Zoom is committed to complying with all applicable privacy laws, rules, and regulations in the jurisdictions within which it operates, including the GDPR."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon faces £637 million fine over GDPR violations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/360444/amazon-faces-ps637-million-fine</link>
                                                                            <description>
                            <![CDATA[ If confirmed, the penalty would be almost 15-times larger than the current record fine ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">odYtyKsHtBXPiBmV5iSRez</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZErfPAYiffC9xxB8h5QZMV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Aug 2021 10:24:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZErfPAYiffC9xxB8h5QZMV-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The exterior of an Amazon Go retail shop]]></media:description>                                                            <media:text><![CDATA[The exterior of an Amazon Go retail shop]]></media:text>
                                <media:title type="plain"><![CDATA[The exterior of an Amazon Go retail shop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZErfPAYiffC9xxB8h5QZMV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon is facing a potential €746 million (approximately £637 million) fine for the unlawful processing of personal data, following a GDPR ruling by Luxembourg’s data protection regulator.</p><p>The ruling was initially made on 15 July but only became public knowledge when mentioned as part of <a href="https://www.sec.gov/ix?doc=/Archives/edgar/data/1018724/000101872421000020/amzn-20210630.htm">Amazon's latest quarterly earnings report</a>. If it goes ahead, the fine would be the largest data protection penalty in industry history.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">General Data Protection Regulation (GDPR) <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/359658/gdpr-turns-three-biggest-fines" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/359658/gdpr-turns-three-biggest-fines">GDPR turns three: The biggest fines so far</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go" data-original-url="/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go">GDPR fines: Where does the money go?</a></p></div></div><p>This €746 million fine would represent a sum that’s more almost 15-times greater than the €50 million penalty that <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/32811/france-issues-google-with-the-heaviest-gdpr-fine-to" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/32811/france-issues-google-with-the-heaviest-gdpr-fine-to">French data regulator CNIL administered against Google</a> in 2019.</p><p>Amazon didn’t explain the specific basis for such a relatively large penalty in its legal filing, nor has the Luxembourg National Commission for Data Protection (CNPD) made the details around the case public.</p><p>The regulator confirmed with <em>IT Pro</em>, however, that the decision was made on the basis of the one-stop-shop principle set out in Article 60 of GDPR.</p><p>This means Luxembourg was nominated as the lead supervisory authority in a case against Amazon based on alleged violations that occurred across borders and in several EU territories. The CNPD was chosen to investigate Amazon because the firm’s European headquarters is based in Luxembourg.</p><p>The CNPD claims the nation’s own local data protection laws have bound the authority to “professional secrecy” when taking regulatory action. According to these laws, details about the case cannot be published - or publicised - until Amazon’s deadline for appeals expires.</p><p>Amazon said the regulator’s decision has been made without merit, and that it plans to defend itself “vigorously”. Although the firm is able to appeal the decision, the regulator didn’t indicate how long this process might take.</p><p>Despite such a large fine cited, there’s also every chance that it can be drastically lowered over the course of regulatory proceedings. For example, the UK’s Information Commissioner’s Office (ICO) had initially issued a notice of intent to fine BA and <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/33989/marriott-fined-99m-for-2018-data-breach" target="_blank" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/33989/marriott-fined-99m-for-2018-data-breach">Marriott</a> £183 million and £99 million respectively in July 2019. This was eventually watered down to <a href="https://www.itpro.com/security/data-breaches/357452/british-airways-dodges-ps183-million-data-breach-fine" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/357452/british-airways-dodges-ps183-million-data-breach-fine">£20 million</a> and <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined">£18.4 million</a> in October 2020, with the ICO citing a number of mitigating circumstances, including the economic effects of the pandemic.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="diNegsB45N5reQt87tPeR4" name="diNegsB45N5reQt87tPeR4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/diNegsB45N5reQt87tPeR4.png" mos="https://cdn.mos.cms.futurecdn.net/diNegsB45N5reQt87tPeR4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The controversial CLOUD Act</strong></p><p class="fancy-box__body-text">The effect on data protection and data security in Germany and the EU</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/360423/the-controversial-cloud-act" data-original-url="/cloud/360423/the-controversial-cloud-act">FREE DOWNLOAD</a></p></div></div><p>Prior to GDPR coming into force, many businesses widely expected the new data protection laws to usher in an era of massive, eye-watering fines that would cripple businesses found to have fallen foul of the rules. This was based on the provision that an organisation can face a fine of up to €20 million or 4% annual turnover, whichever is higher.</p><p>In practice, however, such fines have been a rarity, despite a high volume of cases.</p><p>The Irish data protection regulator too, which is itself the lead supervisory authority in a number of cases against big tech giants, hasn’t yet worked through a lengthy backlog of legal challenges. So far, the Irish Data Protection Commission (DPC) has issued a <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358132/twitter-handed-eu450000-gdpr-fine" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358132/twitter-handed-eu450000-gdpr-fine">€450,000 fine against Twitter</a>, alongside a provisional decision in January 2021 to fine WhatsApp <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/358417/whatsapp-could-face-eu50-million">€50 million</a>, although this is subject to legal review.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>