Deloitte Legal Guide to Cross-Border Secured Transactions

Nyheter

Relevant privacy headlines

Privacy Newsletter

Please find a compilation of the latest relevant privacy headlines below.

The Swedish Authority for Privacy Protection (IMY) initiates an investigation against a Swedish bank once again

The investigation was initiated as several individuals had submitted complaints concerning the identification requirements used by the bank in connection with data subjects exercising their rights under the GDPR (e.g. right to rectification and right to erasure). According to the complaints, the bank has imposed unreasonable requirements with regards to how data subjects should confirm their identities when making a claim to exercise their rights. According to IMY, the investigation aims to examine whether the bank, through its identification requirements, has made it more difficult for individuals to exercise their rights under the GDPR. IMYs press release is available here.

Instagram receives a fine of 405 million euro

Instagram receives a fine of 405 million euros as well as a range of corrective measures issued by The Irish Data Protection Authority (DPA). The fine is as a result of the public disclosure of contact details of children using the Instagram business account feature and a public-by-default setting for personal Instagram accounts. It is the second largest fine that has ever been issued under the GDPR and the third fine issued against Meta-owned companies. The press release of the DPA is available here.

Instagram receives a fine of 405 million euro

Instagram receives a fine of 405 million euros as well as a range of corrective measures issued by The Irish Data Protection Authority (DPA). The fine is as a result of the public disclosure of contact details of children using the Instagram business account feature and a public-by-default setting for personal Instagram accounts. It is the second largest fine that has ever been issued under the GDPR and the third fine issued against Meta-owned companies. The press release of the DPA is available here.

The French DPA (CNIL) issues a fine for inadequate data security measures and for keeping personal data beyond the documented retention period

A French company, providing a web-based search service for official court documents, received a fine of 250 000 euros for keeping personal data beyond the documented retention period and for providing an inadequate level of data security. The decision was initiated after a report from a person who claimed they were able to obtain their user password to the website by simply stating their name to the contact person of the hotline. After CNIL conducted an online check of the website, it was revealed that the company transmitted non-temporary passwords in clear text by email and users could not create a secure password due to the limited password size imposed by the website. The CNIL also discovered that some of the personal data processed by the company was kept beyond the documented retention period for such data. CNILs press release is available here.

EU commission published a draft regulation on cybersecurity

On September 15, the EU Commission published a draft proposal for a new regulation to amend Regulation (EU) 2019/1020 on products with digital elements. The proposed draft aims to ensure that products with digital elements have an adequate level of cybersecurity and that manufacturers of such products are transparent with security properties. Products with digital elements mean any software or hardware that needs any remote data processing in order to function. The proposed regulation would, among other things, impose requirements on manufacturers to conduct and document assessments of the cybersecurity risks their software or hardware products may be exposed to. The EU Commission’s press release is available here.

Questions?

The Deloitte Privacy Team has extensive experience in the privacy field and regularly advices on data protection and information security matters. You are very welcome to contact us if you need our help or if you have any questions.

Fullwidth SCC. Do not delete! This box/component contains JavaScript that is needed on this page. This message will not be visible when page is activated.

Hade du nytta av den här informationen?