Privacy and cybersecurity are incredibly dynamic, and in 2025 we have committed ourselves to a look ahead post every six months, with the next one in July 2025. The new Congress convened on January 3, 2025, and a new administration starts on January 20. Most state legislatures reconvene in early-to-mid January. If you track privacy
France – CNIL
France’s Commission Nationale de l’Informatique et des Libertés (“CNIL”) provides great tools and resources as well.
- CNIL recently updated its Privacy Impact Assessment (PIA) Guides which include application to connected objects, methodology, template and knowledge bases.
- CNIL also recently updated its PIA software tool in four languages that companies can use for compliance.
- CNIL provides
…
Germany – BfDI
Germany’s Bundesbeauftragte für den Datenschutz und die Informationsfreiheit published the Federal Data Protection Act to adapt GDPR. Germany provided some extensive guidance on GDPR here. Germany also publishes the standard data protection model, SDPM, in English on its site. Also available from the site are guidance materials about GDPR from the German Data…
UK ICO
The United Kingdom’s Information Commissioner’s Office (“ICO”) is a great resource for companies looking for clear DPA guidance. The ICO has provided a Guide to the GDPR which is very targeted and comprehensive as well as resources for organizations including several guides. Getting Ready For GDPR Resources is a nice package of information prepared by…
Article 29 Working Party
The European Commission – Data Protection links to the Article 29 Working Party Guidelines which supplement our understanding of GDPR:
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679 (wp251rev.01)
- Guidelines on Personal data breach notification under Regulation 2016/679 (wp250rev.01)
- Guidelines on the application and setting of administrative fines (wp253). In
…
European Commission – Data Protection
The European Commission – Data Protection provides links to EC data protection policies, information and services. The Commission provides the official GDPR text in multiple languages, describes the European Data Protection Board and its responsibilities, provides detailed guidance and resources on data transfers outside the EU, and some focused discussion of the changes to…
Useful Official GDPR Resources
Recently, I have been asked several times where there are good, official resources on GDPR. The following series of posts provide links to these resources. We will post additional resources from time-to-time.
- European Commission – Data Protection
- Article 29 Working Party
- UK ICO
- Germany – BfDI
- France – CNIL
- Visiting With SKW Schwarz at IAPP’s
…
The more people interact with AI, the more they like it – but that doesn’t diminish their privacy fears
According to a recent Genpact study:
- Nearly two-thirds of consumers (63%) are worried that Artificial Intelligence is going to make decisions that will impact their lives without their knowledge
- Less than one-third (30%) are at least “fairly comfortable” with the idea of companies using AI to access their personal data
- Almost three-quarters (71%) say
…
CNIL’s GUIDANCE FOR PROCESSORS – ANSWERS TO YOUR MOST PRESSING QUESTIONS
See European Regulation on the Protection of Personal Data Guide Sub-Contractor Edition, September 2017.
- Are you a contractor within the meaning of European Regulation on data protection?
- Are you subject to EU regulation on data protection?
- What is the main change introduced by the European regulation for contractors?
- What are your obligations as of
…
PIAs & DETERMINATION OF RISK UNDER GDPR – THE LATEST:
The Article 29 Working Party updated the Guidelines on PIAs and evaluation of risk guidance on October 4, 2017:
CNIL created a PIA Infography to outline the main principles. Keep…
Your Car and GDPR
CNIL, the French DPA, published a new Compliance Pack called “Connected Vehicles: A Compliance Pack for Responsible Data Use” on October 17, 2017. CNIL broke its guidance into three scenarios:
- Personal data remains in the car
- Personal data is transmitted externally to provide a service to the individual
- Personal data is transmitted outside
…