Skip to content
Privacy Vox

Privacy Vox

(Data Protection News & Services)

en_GBfr_FR

Menu

  • GDPR News
    • Marketing – Profiling
    • Cookies – Trackers
    • Personal Data Breach
    • CJEU – Schrems II
    • Covid-19
    • Human Resources (HR)
    • Decision (sanction, judgement CJEU etc.)
    • Guidelines (EDPB, Authorities etc.)
  • GDPR at a glance
    • Introduction to GDPR
      • What’s GDPR?
      • Does GDPR apply to your business?
      • Controller or Processor?
      • The Privacy Principles
      • Data Protection by Design and by Default
      • The Legal Bases for Processing Personal Data
    • Data Controller
      • Controller’s obligations under the GDPR
      • Privacy Policy and GDPR: What To Update
      • Consent under the GDPR
      • Record of Processing Activities
      • Data Protection Impact Assessment (DPIA)
      • Personal Data Breach Notification
    • Data Processor
      • Data Processor’s Responsibilities Under the GDPR
      • Record of Processing Activities
    • Data Protection Officer (DPO)
      • When to Appoint a Data Protection Officer
      • Data Protection Officer’s Role and Responsibilities
      • Data Protection Officer: Appointment, Position and Skills
    • Individual’s rights
      • Overview of the Individuals’ Rights Under the GDPR
      • Right to Data Portability
    • Miscellaneous
      • GDPR : International Data Transfers
      • One-Stop-Shop under the GDPR: how does that work?
      • GDPR : Sanction (Administrative fine)
  • About

Author: Arnaud

One-Stop-Shop: The ECJ Clarifies How The Non-Lead Supervisory Authorities May Exercise Its Powers

One-Stop-Shop: The ECJ Clarifies How The Non-Lead Supervisory Authorities May Exercise Its Powers

In its recent decision of June 15, 2021, involving Facebook and the Belgium Data Protection Authority (“DPA”), the European Court of Justice (the “ECJ” or the “Court”) clarified the conditions under which the non-lead  supervisory authorities may exercise their powers

Arnaud 21/06/202122/06/2021 News Read more

The European Commission Updates the Standard Contractual Clauses for International Transfers (and Releases a New Set of Controller to Processor Clauses)

The European Commission Updates the Standard Contractual Clauses for International Transfers (and Releases a New Set of Controller to Processor Clauses)

On June 4, 2021, the European Commission released two new set of contractual clauses :  A set of clauses for personal data transfers from Controller to Processor within the Union  as required under article 28 GDPR (C to P clauses)

Arnaud 10/06/202111/01/2022 News Read more

NDL: Booking.com fined €475,000 for a late data breach notification

NDL: Booking.com fined €475,000 for a late data breach notification

The Dutch Data Protection Authority (DPA) has imposed a €475,000 fine on Booking.com because the company reported a data breach to the DPA 22 days later instead of whithin the required 72 hours.

When the breach occurred, criminals accessed the personal data of over 4,000 customers including the payment card information of almost 300 people.

Arnaud 19/04/202124/04/2021 News Read more

Spain (AEPD): 6M€ fine on Caixabank for unlawful data processing and insufficient information

Spain (AEPD): 6M€ fine on Caixabank for unlawful data processing and insufficient information

The Spanish Data Protection Authority (AEPD) imposed a total fine of 6.000.000 EUR on CAIXABANK, S.A., for : unlawful processing of its clients’ personal data (4.000.000 EUR); and not providing sufficient information regarding the processing of personal data (2.000.000 EUR). 

Arnaud 19/04/202119/04/2021 News Read more

Schrems II – Data transfers : The Bavarian DPA Responds to Recurring Criticism by Preventing a Company from Using Mailchimps

Schrems II – Data transfers : The Bavarian DPA Responds to Recurring Criticism by Preventing a Company from Using Mailchimps

Following the publication of its response to a data subject  in a German newspapers the “Standard“, the Bavarian Data Protection Authority (DPA) took this opportunity to respond to recurring criticism and draw the attention of people on its actual enforcement

Arnaud 15/04/202115/04/2021 News Read more
  • « Previous
  • Next »

Legal

  • Terms of Use
  • Cookies Policy
  • Photo Credit

Categories

  • Data Controller
  • Data Processor
  • Data Protection Officer (DPO)
  • Individual's rights
  • Introduction to GDPR
  • Miscellaneous
  • News
  • Controller or Processor?
  • One-Stop-Shop under the GDPR: how does that work?
  • The Legal Bases for Processing Personal Data
  • The Privacy Principles
  • Data Protection Impact Assessment (DPIA)
Copyright © 2025 Privacy Vox. All rights reserved. Theme Spacious by ThemeGrill. Powered by: WordPress.
  • Terms of Use
  • Cookies Policy
  • Photo Credit