EU General Data Protection Regulation tagged posts

Don’t call us. We’ll call you. And steal your data.

AT&T image of data theftWhile the EU General Data Protection Regulation (GDPR) requirements have yet to be finalised, 20 years of European jurisprudence is a strong indication of the direction of travel where the supervisory authorities are going to clamp down hard on those organisations and their outsourcing providers that violate the new minimum standards for data protection.

And if you’re in any doubt how hard this will impact the telecoms sector, then you should look no further than what’s just happened to AT&T earlier this week in the US to get a taste of what we can expect to see here in the EU in the wake of the GDPR.

The US Federal Communications Commission (FCC) reached a settlement wit...

Read More

Financial Services face controls on marketing under GDPR

_DSC8306Photograph by David Graeme-Baker

Earlier this week, the Worshipful Company of Marketors, the livery company representing the interests of marketing professionals in the City and the Financial Services Forum held a joint seminar on the subject of the EU General Data Protection Regulation (GDPR) at Cass Business School, London. This was the first time that both organisations had collaborated on an issue that impacts the financial services sector more than any other sector.

Those taking part (left to right) were Martin Hickley, data governance, protection and privacy expert; Hazel Grant, partner and head of privacy and information law at Fieldfisher; Ardi Kolah, director of Go...

Read More

Why Obama’s body language is very European

Mirror and matchingOver the next 24 hours all eyes will be on US President Barak Obama as he plays host to the British PM David Cameron at the White House.

And whilst Anglo-American relations are warm and friendly, Obama’s body language will reveal his pan-European tendencies when it comes to security and data protection.

This is in sharp contrast to the reticence of David Cameron to an intra-country solution as advocated by European Commission President Jean-Claude Juncke who’s determined to fast-track the EU General Data Protection Regulation this year.

David Cameron and Barak Obama have a working dinner tomorrow night and will meet in the Oval Office on Friday...

Read More

Delays in agreeing wording of EU General Data Protection Regulation (GDPR) is “bad for democracy”

cameron06june14-480632Impatience with the progress of the forthcoming EU General Data Protection Regulation (GDPR) is starting to grow within the European Union.

A recent joint declaration adopted by representatives of the German, Austrian, Belgian, Croatian, French, Greek, Hungarian, Lithuanian, Luxembourg, Dutch, Portuguese, Czech, Romanian, UK, Slovakian and Swedish  parliaments called on European legislators to adopt the GDPR “by 2015”.

German Green MEP Jan Philipp Albrecht, vice chairman of the civil liberties committee at the European Parliament warned this week that failure to agree on the new security and data protection rules was “bad for democracy” as this left European citizens exposed...

Read More

Fingerprint technology is unsafe as a security measure claims leading cyber crime and compliance expert

121019_fingerprint_machine_lgThere are growing concerns among data protection experts that current safeguards in place for the collection and storage of fingerprints is deeply flawed and are likely to be in breach of the forthcoming EU General Data Protection Regulation, expected to be approved in 2015.

At the convention of Chaos Computer Club, a computer hacker known as “Starbug” claims to have cloned the thumbprint of German Defence Minister Ursula von der Leyen simply by using a standard smartphone and other pictures taken of her when she spoke at a conference recently.

Fingerprint identification is a commonplace security measure...

Read More

Cowboy marketers face record fines in the New Year

Cowboy-marketersCurrent law

Under EU Privacy and Electronic Communications Regulations (PECR), organisations and companies are prohibited from transmitting or instigating the transmission of unsolicited electronic communications to consumers for the purposes of direct marketing unless the person receiving those communications has provided prior consent for the messages to be sent.

Companies also mustn’t disguise or conceal their identity in the messages or use invalid addresses where recipients of the messages would send responses to ask for the messages to stop being sent.

Marketers can send direct marketing via electronic mail to consumers if they have “obtained the contact details of th...

Read More

Google hit with threat of massive fine by Dutch Regulator for data breach

Google AccountAs reported in the Financial Times (London, 15 December 2015), Google faces its largest ever fine from a European regulator after the Dutch Data Protection Agency threatened Google with a €15m fine over the way its stores personal data.

The Dutch Regulator demanded that Google asks users for “unambiguous consent” before it can share their personal details between its services, such as Google Maps and YouTube, the video-sharing site.

It also mandated that the company clarify its privacy policy so users know which bits of personal data are used by its different services.

The ruling comes in the wake of the meeting of Council of Ministers that are looking at ways of makin...

Read More

Sony try to shut the stable door after the horse has bolted. It may not work.

Sony PictureTri_Star_pictures_flying_horses Entertainment (SPE) has warned media owners they could face legal action for substantial damages if they report the contents of stolen documents that were leaked online following a cyber-attack on Sony in November 2014.

In a blunt letter written by a top US law firm, SPE has requested media organisations including The New York Times, Wall Street Journal, Bloomberg News and The Hollywood Reporter to destroy “stolen information” which includes documents, personal data and emails that’s sensitive data that is now presumed to be in the public domain.

In a thinly veiled threat, the letter warned: “If you don’t comply with this request and the stolen informa...

Read More

Unlocking the power of direct marketing under the new EU Regulation

EU data protection keyAt a meeting of the Justice and Home Affairs, part of the EU Council of Ministers that took place on 4-5 December 2014, the forthcoming EU General Data Protection Regulation took a further step to becoming adopted across all 28 EU Member States.

The meeting, attended by Chris Grayling, Lord Chancellor and Teresa May, Home Secretary and chaired by Andrea Orlando, Italian Minister of Justice and President of the Council marks a tipping point in the harmonization of data protection laws across all 28 EU Member States.

At that meeting, the EU Council of Ministers gained partial consensus on two important and inter-related points with respect to data security and protection that ...

Read More

What is meant by “data breach”?

Hacker typing on a laptopThis was the subject of discussion with Martin Hickley, a leading expert on all things cyber-crime and data protection related. Martin will be speaking at a special event that I’m chairing on 27 January 2015 at Cass Business School that will examine the impact of the EU General Data Protection Regulation on the financial services sector and what should be done in this current transition period ahead of the EU Regulation being activated across the European Union, possibly next year.

Two words dominated the conversation with Martin: DATA BREACH.

This is a term that’s being used frequently in the media and elsewhere and indeed is referred in the current Data Protection Act 1998...

Read More