MX:Monitor
  • Home
  • UX:Inspector
  • DP:Monitor
  • About
  • Contact
  • Blog

Data Protection in the News - August 2021

18/8/2021

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
In July 2021, the EU began accepting proposals for a study of the impact of recent developments in adtech and their impact on privacy, the publishers, and advertisers.

In France, the data privacy regulator (CNIL) continues its pursuit of organisations with non-compliant cookie regimes and is effectively supported in Germany by Max Schrems’ organisation (NOYB) which has filed 422 formal complaints of organisations with cookie non-compliance with 10 regulatory authorities.

Much of the news focused on China and its increasingly aggressive stance on the data privacy requirements of national and global tech giants, and restriction of processing data in perceived conflict with the national interest.

The US and EU continue to attempt to breathe life back into the Privacy Shield Program and indicate that discussions are advanced.

These and other news items detailed below.
VIEW FULL NEWSLETTER

Data Protection in the News - July 2021

12/7/2021

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
Debate about the roll out of revised EU Standard Contractual Clauses (SCCs), and related guidance about export of personal data considering the Schrems II legal outcome, has featured heavily this month.

The EU formally granted adequacy status to the UK and gave the green light to country privacy regulators to pursue action against organizations regarding transgression in their own countries, as opposed to limiting their activity to coordination of combined action through one EU lead regulator. Tech giants (and others) potentially having to defend on multiple fronts.

In the USA, while Colorado passed its privacy act, there remains speculation that federal legislation maybe may be slipping down the Presidential priority list.

In the world of privacy activists, NOYB launch their campaign targeting organizations that do not have compliant cookie regimes, while the Irish Council for Civil Liberty (ICCL) acted in Germany against IAB Techlab in challenging the privacy aspects of Real Time bidding.

In a month where Google quietly announced a delay in the retirement of third-party cookie support in Chrome to mid-2023, Amazon are facing a $425m fine in Luxembourg over practices regarding the collection and use of personal data. The Luxembourg regulator appears to be super active, with 18 decisions published in June.
VIEW FULL NEWSLETTER

Data Protection in the News - June 2021

18/6/2021

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
The last few days have seen the publication by the EU of long awaited revised Standard Contractual Clauses (SCCs) intended to better reflect the GDPR. The new modular version of the SCCs, while widening how they can be applied, introduces some complexity for organizations. Their use is limited for contracts with entities that are not subject to the GDPR, and this is a trip hazard. Many overseas processors are subject to GDPR as a result of the existing extra-territorial scope defined under Article 3, so that leaves the question of when SCCs should be used.
 

There has been noise in the EU parliament from some vocal MEPs on the granting of ‘adequacy status to the UK’. Those that are dissatisfied with the outcome may have to rely on the 4-year sunset period for that agreement and challenge any renewal at that point. There have also been voices of censure and dissatisfaction over the lack of apparent vigour and urgency that the Irish regulator (DPC) has shown with regard to pursuing actions against the tech giants that fall within its jurisdiction. The EU Parliament voted to pressure its Commission to begin infringement proceedings against the Irish DPC.

Bowing to the related concern about exporting personal data from the EU, Microsoft has announced that it will provide infrastructure for its customers to host and process all data inside the EU.

Watch out for cookie compliance! NYB, the organization behind Max Schrems, the author of the downfall of the US Privacy Shield, is beginning a programmatic review of the cookie notifications of thousands of commercial EU websites to expose those that are non-compliant in providing ease of ‘opt out’. Expect some significant findings in this area.
view full newsletter

Data Protection in the News - May 2021

17/5/2021

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
In our heartland of B2B, the UK and EU continue to move towards the granting of an adequacy provision to allow for the free flow of data. There has been some pushback within EU circles, resulting in the EU stating that they reserve the right to withdraw such status if the UK goes off piste. 

The EU also claims to be close to the release of revised and more flexible standard contractual clauses (SCC) to allow the flow of data to jurisdictions that do not carry the EU adequacy status. This will help close the legality chasm in the current transfer of data between the EU and USA, created when the Privacy Shield arrangement was struck down. (The UK will publish its own version of SCCs.)

There is ‘noise’ amongst EU regulators, who are in some unseemly tussles over the ‘one stop shop’ mechanism, which of the regulators can pursue the global tech giants, and whether those in the frame as ‘lead regulator’ are doing a decent job.

Pressure continues in the US for federal privacy legislation as the region becomes increasingly complex with more and more disparate state laws being passed.

China has made moves proposing a ‘consent’ model on tech companies through a draft Personal Information Protection Law (PIPL).

Also, an interesting discussion on the topical issue of video interviews for job applicants and the related privacy implications.
VIEW FULL NEWSLETTER

Data Protection in the News - April 2021

14/4/2021

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
US legislative developments feature highly in the last thirty days in Virginia, Arizona, Florida, Colorado and at federal level with the Information Transparency and Personal Data Control Act, the first federal level activity of 2021.​

In Europe, the UK and EU continue the dance that will determine the expected adequacy decision for the UK enabling the unencumbered bilateral movement of personal data. The UK makes noises about a more progressive UK data privacy regime and its sovereign right to agree other data sharing arrangements, which unsettles the EU.

Meanwhile, the EU and US announce that they will step up efforts to agree a data sharing agreement, but with little conviction or credibility. Most informed sources see significant challenges to any such agreement.

Pragmatic corporate data privacy professionals remain focused on the inching forward of EU ePrivacy legislation and for clarity over approved legal clauses to export data from the EU and the US. Corporates continue to export data anyway, now technically illegally, and wait for the army of lawyers and legislators to get a grip with the real world and catch up.

Away from politics and into the corporate fray, Apple begins to flex its muscles through blocking apps that do not comply with their new (non-cookie) privacy regime. Fun times in Data Privacy!
VIEW FULL NEWSLETTER

Data Protection in the News - March 2021

15/3/2021

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
The debate and discussion about the legality of international transfers of data continued during February, the EU institutions of EDPB (European Data Protection Board) and EDPS (Supervisor) providing opinion on the revised standard contractual clauses. These ‘SCCs’ are now deemed central to the ability to transfer personal data outside the EU and its approved partners deemed to have ‘adequate’ data protection regimes.

Meanwhile the UK still pursues and expects adequacy status to be granted by the EU, while at the same time messaging the benefits of an independent regime where the benefits of data sharing are recognised alongside the importance of its protection. Of note, the upcoming ePR will become law in the EU but not in the UK where its predecessor (PECR) will still be the local statute of reference. A potential divergence will be the subject matter of discussion over coming months.

In the US, the weight of media coverage suggests a continued expectation of federal data protection legislation as more states take local action (Florida, Virginia, Minnesota) a notable exception being North Dakota where legislation was voted down.

Amongst the data ‘ethic topics’ is the use of ‘pixel’ tracking tactics, where content such as outbound emails and web pages contain invisible pixels that track a user’s engagement with content. While such use should be disclosed in privacy policies, the reality is that consumers are often unaware of this tracking of their activity. While this might be legal, is it ethical?
View Full Newsletter

Data Protection in the News - February 2021

15/2/2021

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
​Brexit discussions continue, with UK Government sources indicating that a positive UK adequacy decision is likely within the extended transitional window (open to June 2021). Observers wonder whether this is an entirely objective assessment or whether the EU might choose to exact further pressure on the UK.

The Portuguese presidency of the council of the EU has brought further impetus to agreement of the terms of the much-discussed ePrivacy legislation, now ready for presentation to the Parliament.

In the US, expectation and speculation continues around the need for, and likelihood of, federal data privacy law. Certainly, the privacy debate shows no sign of abating.

In APAC, the ten member states of ASEAN (Singapore, Brunei, Cambodia, Indonesia, Lao, Malaysia, Myanmar, Philippines, Thailand and Vietnam) approved the new Data Management Framework (DMF) and Model Contractual Clauses for Cross Border Data Flows.

Tech companies continue to posture and wrestle over tracking technologies, with Apple assuming a moral high ground in the scheduled withdrawal of cookies and requiring the user to opt in to IDFA (Identifier for Advertisers), a move that threatens a Google revenue stream heavily dependent on the ability to target users based on cookie deployment. This move could be disruptive for organisations heavily invested in cookie-based targeted advertising.

WhatsApp has seen a large negative reaction to its announced changes in privacy terms and data sharing agreements with Facebook, and an increase in users choosing alternative messaging platforms.

At a more tactical level, organisations are reminded that the ‘new normal’ of working from home carries the risk of employees processing personal data in ways that pose a risk to its security.
view full newsletter

Data Protection in the News - January 2021

18/1/2021

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
Big news items in Europe included the closure of negotiations of the exit of the UK from the EU, including a four-month window into 2021 to allow continued uninterrupted flow of personal data between the UK and the EU; that window to enable a stable and longer-term agreement. 

UK-based data controllers have line of sight to potential outcomes and related short-term implications of BREXIT. On the related theme of data transfers, discussions continue in the US and EU to explore how to fix the broken US Privacy Shield Model. In both the EU and US, privacy agendas continue to gain ground, the EU tabling a Digital Services Act and revised draft of ePR, and speculation that 2021 could be the year when state initiatives pressure the US Government into federal legislation.

Meanwhile the big tech companies continue to attempt to fend off litigation around the globe with regard to their data harvesting practices, and Google and Apple spar over technologies that enable the ad tech markets and their respective revenue streams.

China extends its data privacy laws, as does Canada, bringing them closer to the European GDPR. 2021 promises to maintain momentum of data privacy requirements and further alignment in approach across global jurisdictions.
view full newsletter

Data Protection in the News - December 2020

13/12/2020

 
Picture
Expert commentary from Tim Lennard with a roundup of recent data privacy stories
from around the globe
The calendar year promises to end with a flourish of activity in the Data Privacy and Protection world.

Recent weeks in the EU have witnessed the consultation of newly drafted Standard Contractual Clauses to facilitate international data transfers. New guidelines in data privacy by design have been issued, and the data strategy for the region to wrestle back control from US tech giants has been further communicated.

There has been some wrestling between EU national regulators, with the Irish coming under criticism for failure to act against Google, and the French Regulator (CNIL) announcing large fines under the nose of the Irish Regulator against Google (€40m) and Amazon (€35m), citing legislation predating the GDPR. At the time of writing, BREXIT related issues are still ‘in the air’.

The US has seen the enactment of the CPRA in California, adding to the baseline of the CCPA by introducing rules around ‘do not share my data’ and impacting the use of personal data in behavioural advertising tactics. The momentum of change is showing no signs of slowing, and the pressure for federal legislation will be a factor for the new US Presidency in 2021.

Canada introduced a bill to overhaul their data privacy legal regime, Australia brought in the Data Availability and Transparency Bill, and New Zealand’s Privacy Act 2020 came into force.

The ad tech industry continues to be challenged, not only with the action in France against Google and Amazon for cookie violations, but also with Max Schrems, the man behind the striking down of EU Privacy Shield Action, now acting against Apple in their use of Identifier for Advertiser (IDFA) technology on iphones.
view FULL NEWSLETTER

Audience Smash and Grab?

27/11/2020

 
Picture
FreeImages.com/Aaron Gardner
Why audience inflation doesn't work 
​
Is your marketing team tempted to grab as big an audience as possible for each of their outbound campaigns? Why wouldn’t they? After all they are only measured on number of responses. They just load up that big outbound communications gun and ‘FIRE!’.

Read More
<<Previous

    AuthorS

    Tim Lennard
    ​Andrew Roberts

    ARTICLES

    All
    Audience Smash And Grab?
    Lost In Space
    Newsletter

    Archives

    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    June 2020
    May 2020
    April 2020

Site powered by Weebly. Managed by SiteGround
  • Home
  • UX:Inspector
  • DP:Monitor
  • About
  • Contact
  • Blog