Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts
By Matt Klinger

In late February, Isabelle Falque-Pierrotin was elected to serve as the new chairwoman of the European Union's Article 29 Working Party, a group that plays an advisory role on data protection issues to both the European Commission and to the E.U. member states.  

Falque-Pierrotin will face two major challenges in her new role: transitioning the E.U. to a new data protection regulation that likely will be implemented in the coming months and promoting international cooperation between data protection authorities. 

In addition to serving a two year term as head of the Working Party, Falque-Pierrotin will continue to serve as the Chairwoman of the French Data Protection Authority (CNIL), a post she has held since 2011.  

Earlier this year the CNIL handed down its highest financial penalty ever when it sanctioned Google 150,000 euros for violating several provisions of the French Data Protection Act.  
By Matt Klinger

In October, the European Commission's official data protection advisory group, the Article 29 Working Party, issued its latest guidance for complying with the EU's e-Privacy Directive (affectionately known as the "Cookie Directive").

Among other provisions the new guidance provides that when accessing a website, users must have access to "all necessary information" about the types and purposes of cookies used by the site.  In addition, the guidance clarifies that a user's consent to place cookies on a device, which is required by the Cookie Directive, must be sought before cookies are set or read.  Meanwhile, the Wall Street Journal reports that Google, Microsoft, and Facebook are each developing online tracking methods that could eventually make cookies, and the new guidance, obsolete.
By Matt Klinger

Data privacy officials from across the globe gathered in Poland last week for the 35th Annual International Conference of Data Protection and Privacy Commissioners.  The conference attendees adopted eight resolutions on various privacy issues including a call for increased cross-border cooperation in data privacy investigations and recommended safeguards for parties that engage in profiling. 

Attendees also adopted a declaration addressing the "appification" of society. The declaration emphasizes that app developers should only collect data necessary for their product's performance and calls on operating system providers to offer more granular privacy settings on mobile devices.  The commissioners warned that if their efforts to encourage better privacy practices regarding apps do not have "sufficient effect," they "will be ready to enforce . . .  legislation in a global effort to reclaim user control."
By Matt Klinger

The Organization for Economic Cooperation and Development (OECD) recently updated its Guidelines governing the Protection of Privacy and Transborder Flows of Personal Data ("Revised Guidelines").   While the set of eight principles established in the original guidelines published in 1980 remain intact, the Revised Guidelines introduce at least three new concepts: (1) the importance of a coordinated national privacy strategy; (2) the need for privacy management programs within organizations; and (3) data breach security notification regimes.

In addition, the OECD has highlighted two themes that run throughout the Revised Guidelines.  First is a "focus on the practical implementation of privacy protection through an approach grounded in risk management."  Second is the "need for greater efforts to address the global dimension of privacy through improved interoperability." 

These revisions help modernize the guidelines to accommodate vast changes in data generation and flows since 1980.  They also serve, however, to highlight the enduring nature of the OECD's data protection principles.