Data protection

EU Data Protection Party warns the trilogue negotiators not to relax limits on how data controllers can use personal data after it has been collected

When it comes to further processing of personal data, will the EU institutions be able to agree on how to deal with purpose incompatibility? The extent to which businesses can justify further processing of personal data for new purposes (that is, for reasons distinct from the original purpose for which the data was collected) can … Continue reading

Data protection / drones / Privacy / Privacy impact assessment

Opinion on drones released by EU Data Protection Working Party

“Technology is neither good nor bad; nor is it neutral” – How far might future usage of drone technology affect the very fabric of the societies in which we live? The Article 29 EU Working Party (WP) has issued an Opinion about the data protection and privacy implications of utilising unmanned aerial systems (“drones”). This … Continue reading

Data protection / pseudonymisation / Risk-based approach

Council reaches general agreement on proposed Data Protection Regulation, but disagreements remain in view

‘A single road ahead or cross-roads reached?’ – Is the aim of EU harmonisation of data protection rules disappearing out of sight? On 15 June, the Council of the EU announced that it had agreed a general approach to the draft Regulation on the protection of individuals with regard to the processing of personal data … Continue reading

big data / Data protection

Businesses engaged in ‘big data’ personal data processing should consider carefully whether they have ‘legitimate interests’ grounds to justify their activities, says ICO

How exactly should data controllers carry out a ‘balance of interests’ test between their interests and the interests of data subjects? The application of data protection rules to big data technologies raises a number of legal and compliance issues, some of which I highlighted in my recent post about the latest comments from the Information … Continue reading

Biometrics

EU Court of Justice rules on Regulation regarding standards for collecting and using biometric data in passport production

…But side-steps the bigger issue about the compatibility of possible secondary use and storage of such biometric data with privacy and data protection law With the development of biometric technology and its expanding use in the public and the private sector, privacy and security concerns are increasingly growing and formal guidance correspondingly sought on the … Continue reading

anonymisation / big data / Data protection / Privacy / pseudonymisation

The Council of the EU and the proposed Genaral Data Protection Regulation… And what about pseudonymous data?

NGOs (non-governmental organisations) have been doing a good job recently in trying to explain where things stand in the process of re-drafting [and maybe one day adopting] the General Data Protection Regulation (GDPR). You might remember that on 25 January 2012, the European Commission released a Proposed Revised Data Protection Legislative Framework, including the GDPR. … Continue reading

big data / consent / Data protection / health data / Privacy / sensitive data

Article 29 Working Party on the concept of health data: could it mean that we need to adapt the definition of health data as well as that of personal data?

On 5 February 2015, the Article 29 EU Data Protection Working Party (WP) issued a letter addressed to Paul Timmers – the Director of Sustainable and Secure Society at the European Commission. Within the Annex of this letter, the WP identifies relevant criteria to determine when data processed by lifestyle and wellbeing apps and devices … Continue reading

Breach notification / Data protection / Privacy / Privacy impact assessment / Security

‘Nothing is agreed until everything is agreed’… but still a new version of Chapter IV of the proposed General Data Protection Regulation has been released!

The Council of the European Union has agreed on a “partial general approach” when reviewing specific aspects of the proposed General Data Protection Regulation (GDPR) in a note issued on the 3rd of October 2014 for publication in the Council Register. In particular, the note contains a revised version of the draft text of Chapter … Continue reading