{"id":11074,"date":"2025-08-18T16:35:54","date_gmt":"2025-08-18T14:35:54","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=11074"},"modified":"2025-08-19T11:07:52","modified_gmt":"2025-08-19T09:07:52","slug":"data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/","title":{"rendered":"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d &#8211; Estonian regulator"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">How is data protection related to information security?&nbsp;<\/h4>\n\n\n\n<p>The goal of information security is to protect an organisation&#8217;s business processes. This means responsibility for the security of the entire operating system and the ability to resist any activities that threaten the <a href=\"https:\/\/www.aki.ee\/uudised\/andmeturbe-saladused-kuidas-oma-andmeid-ja-organisatsiooni-varjatud-ohtude-eest-kaitsta\">availability, authenticity, integrity, and confidentiality of data processed<\/a> in the system or the services provided and accessed through the system, according to the Estonian data protection regulator.<\/p>\n\n\n\n<p>The information assets include all IT resources \u2013 hardware, software, various data communication devices, etc. However, people working in an organisation and customers can also be considered information assets. Therefore, it can be said that data protection and information security are like two sides of the same coin: <strong>data protection determines the basic principles of personal data processing, while information security helps to implement these principles<\/strong>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><a href=\"#newslettersignup\"><code><strong><mark style=\"background-color:#fce4d3;color:#985fd2\" class=\"has-inline-color\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/mark><\/strong><\/code><\/a><\/h4>\n\n\n\n<p>Beyond the simple fact that it makes good business sense to ensure information security and protect assets, the obligation to implement information security comes among other things from data protection laws, which state that personal data security must be ensured by appropriate and secure measures. This means that <strong>each situation must be assessed individually<\/strong>. To start with:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Map out what your organisation does and what business processes it involves.&nbsp;<\/li>\n\n\n\n<li>Identify the assets you have in place\u2014whether they\u2019re customer data, documents, employees, information systems, or security equipment.&nbsp;<\/li>\n\n\n\n<li>Don\u2019t forget your \u201cglobal defense zone\u201d: your physical office, home office, coworking spaces, and other locations where your organisation\u2019s assets and information might be located.<\/li>\n\n\n\n<li>If something major happens in any of these components, you need to know immediately if and how it will impact your organisation.<\/li>\n<\/ul>\n\n\n\n<p>As a general approach, try to process as little personal data as necessary and only when needed, stresses the Estonian regulator.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>List of AI companies signed up to the EU Code of Practice<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfP2EhexOLHckb7cHDN02vNFXrCzII2HkhShProckz88KuBCgu3yikEBp4eXHfiExUAs06ENaymi0OUhbHtI4gymSXtkSP_96XfnwvmKE3_PT9atE--RxlP2E33w64nhDdzqAPpGQ?key=ljFrlDUcHoy4fWtTbATh1g\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Commission has published the full list of signatories to the EU&#8217;s generative AI Code of Practice initiative so far, known also as the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/contents-code-gpai\">Code of Practice<\/a> for General Purpose AIs (GPAIs), published on July 10, 2025. This will reduce their administrative burden and give them more legal certainty than if they proved compliance through other methods. <\/p>\n<\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>Among signatories there are: <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/contents-code-gpai#ecl-inpage-Signatories-of-the-AI-Pact\">Amazon, Anthropic, Google, IBM, OpenAI, Microsoft, Mistral AI and a dozen other<\/a> companies, (some signatories may not appear immediately on the list). In addition, xAI signed up to the Safety and Security Chapter; this means that it will have to <a href=\"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/\">demonstrate compliance<\/a> with the AI Act\u2019s obligations concerning transparency and copyright via alternative adequate means.<\/p>\n\n\n\n<p>The code has also been complemented by <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act\">Commission guidelines<\/a> and the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/faqs\/questions-and-answers-code-practice-general-purpose-ai\">Q&amp;A<\/a> on key concepts related to general-purpose AI models.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<p><strong>European Biotech Act: <\/strong>The Commission opened a consultation, until 10 November, as part of the development of the European Biotech Act. It will propose a series of measures to create an enabling environment to accelerate the transition of biotech products from laboratory to factory and to the market, while maintaining the highest safety standards for the protection of the population and the environment. The act will address growing <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/14627-Biotech-Act_en\">dependencies in biotech on data, storage, computing power, and AI<\/a>.&nbsp;<\/p>\n\n\n\n<p>In the EU, biotechnology reached a gross value added in 2022 of 38.1 billion euros: the highest contribution came from medical and pharmaceutical biotechnologies, and the fastest-growing area was industrial biotechnology. At the same time, European biotech companies face an opportunity gap, with the US having twice as many early-stage venture capital deals and three times as many late-stage deals. Over the last six years, 66 of the 67 biotech companies going public have targeted the US NASDAQ rather than European stock markets.&nbsp;<\/p>\n\n\n\n<p><strong>California privacy updates: <\/strong>The California Privacy Protection Agency (CPPA) has filed a judicial action seeking to enforce an<a href=\"https:\/\/cppa.ca.gov\/announcements\/2025\/20250806.html\"> investigative subpoena against Tractor Supply Company, a Fortune 500 company<\/a> that bills itself as the nation&#8217;s largest rural lifestyle retailer. The CPPA&#8217;s petition alleges that Tractor Supply failed to comply with a subpoena seeking information about the company&#8217;s compliance with the California Consumer Privacy Act of 2018. The petition marks the CPPA&#8217;s first public disclosure of an ongoing investigation into a company and its first judicial action to enforce an investigative request. The agency has been investigating whether Tractor Supply failed to honour Californians&#8217; right to opt out of the sale and sharing of their personal information online.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXc8TX1lqtUz7cj-0GowdJiZOE6vwXxB2Bx5PQG8lr5ztQ3kPJqTjO1FM-yG9y62ydhmr0eQUPCLwXa8IwsN3tIxobzFi7v0UIxmbOgJwsTWemXmf__TqURc2NIUco0TJfXoUZFtpg?key=ljFrlDUcHoy4fWtTbATh1g\" alt=\"information security\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>GDPR from A to Z:<\/strong>&nbsp; The German Federal Data Protection Commissioner (BfDI) has updated a <a href=\"https:\/\/www.bfdi.bund.de\/SharedDocs\/Kurzmeldungen\/DE\/2025\/14-aktualisierte-Broschuere.html?nn=251928\">catalogue that provides a compact compilation of the most important legal texts<\/a>: the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). In addition to the legal texts and the references to the GDPR, it contains explanations of specific topics and vague legal terms.<\/p>\n<\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p><strong>Data memorisation in LLMs:<\/strong> Additionally, the BfDI has finished its <a href=\"https:\/\/www.bfdi.bund.de\/SharedDocs\/Downloads\/EN\/Konsultationsverfahren\/4_KI-Modelle-pbD\/Konsultationspapier-KI.pdf?__blob=publicationFile&amp;v=2\">consultation on processing personal data in large language models<\/a> in a way that complies with data protection laws. Civil society, industry, and scientific groups were all included in the consultation. It looked for information about the <a href=\"https:\/\/www.bfdi.bund.de\/SharedDocs\/Downloads\/DE\/Konsultationsverfahren\/4_KI-Modelle-pbD\/Konsultationspapier-KI.pdf?__blob=publicationFile&amp;v=2\">limits of anonymisation, the memorisation of personal information, the dangers of data extraction, and the protection of the rights of data subjects<\/a> under the GDPR in AI systems.<\/p>\n\n\n\n<p><strong>AI in healthcare: <\/strong>The EU Publication Office offers a study on on the deployment of AI in healthcare. Present-day healthcare systems face several complex challenges, including rising demand due to an ageing population, increasing prevalence of chronic and complex conditions, rising costs, and shortages in the healthcare workforce. AI has the potential to address some of these by <a href=\"https:\/\/op.europa.eu\/en\/publication-detail\/-\/publication\/9ddf7bf8-62bf-11f0-bf4e-01aa75ed71a1\/language-en\">improving operational efficiency, reducing administrative burdens, and enhancing diagnosis and treatment<\/a> pathways.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>E-store data minimisation<\/strong><\/h4>\n\n\n\n<p>The Latvian DVI explains <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-kads-ir-minimalais-datu-apjoms-lai-noformetu-pasutijumu-e-veikala\">what is the minimum amount of data to place an order in an e-store<\/a>. In order to ensure the fulfillment of an order, certain personal data must be collected and processed. This process can be conditionally called a mutual agreement. The following data is required to place an order:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>customer&#8217;s name and surname (for indication in a supporting document, for example, an invoice);<\/li>\n\n\n\n<li>email address (for sending invoices and order status messages);<\/li>\n\n\n\n<li>phone number (to ensure delivery, the courier also receives this information);<\/li>\n\n\n\n<li>delivery address or parcel machine address (depending on the selected delivery method).<\/li>\n<\/ul>\n\n\n\n<p>The merchant must be able to clearly indicate why each type of data is necessary. For example, first and last name is necessary to fulfill a legal obligation. Other data, on the other hand, is necessary to fulfill the requirements of the contract. For example, i<a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-kads-ir-minimalais-datu-apjoms-lai-noformetu-pasutijumu-e-veikala\">f the service is \u201cintangible\u201d (online courses), first name, last name and email address are sufficient, which are necessary for sending the invoice and access data<\/a>. A merchant may also need additional information if the product or service is individually tailored to the customer (eg, tailored clothing, selection of skin care products manufacturing of spectacles). <\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcN0I2h21ATnDOPNsI9Dm1zTA2u5TC3jlj1TzWFhbA01Mvo4fAc_fOABmlcTeOcSA4qhqzlmikkObcGLZOQz312PBftCNnElO3oiz2eBYDweMrEDJdo8bM1DKrs2e7VvMqFnaItQw?key=ljFrlDUcHoy4fWtTbATh1g\" alt=\"information security\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>Customer data may only be used for the purposes originally specified. It may not be transferred to other parties unless there is a legal basis for this, such as the customer&#8217;s consent, a legal obligation or a legitimate interest. It may also be justified to use the data for related purposes such as archiving, if this does not conflict with the original purpose of obtaining the data.<\/p>\n<\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Data deletion request<\/strong><\/h4>\n\n\n\n<p>The DVI has also tried to answer the question: <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-ja-persona-pieprasijusi-dzest-vinas-datus-kas-apstradati-uz-piekrisanas-pamata-vai-jadzes-ari-pats-pieprasijums\">Should the deletion request itself be erased if someone has asked for data processed with their consent to be deleted?<\/a> If a person withdraws consent to the processing of their data and requests the deletion of all data related to this consent, the organisation is obliged to stop processing this data as soon as possible and delete it, unless there is another legal basis for continuing to store or use it. This means that all data that was collected on the basis of consent must be deleted (eg, the person being removed from the list of recipients of commercial communications).<\/p>\n\n\n\n<p>However, the request document itself, by which the person withdraws consent, as well as the organisation&#8217;s response to it, cannot be deleted at the same time as the aforementioned data, since the basis for processing such information is not the person&#8217;s consent within the meaning of the GDPR. They may be stored to fulfill the institution&#8217;s interests in managing its documentation and ensuring the protection of its rights (so that, if necessary, it can be confirmed that the request has been received, fulfilled and when it occurred).<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More official guidance<\/h4>\n\n\n\n<p><strong>Biometrics: <\/strong>Canada\u2019s Privacy Commissioner has published guidance on biometrics for the public and private sectors. While biometrics can enhance security and help in service delivery, they can also raise privacy issues. Biometric information is intimately linked to an individual\u2019s body and is often unique, and <a href=\"https:\/\/www.priv.gc.ca\/en\/opc-news\/news-and-announcements\/2025\/nr-c_250811\/\">unlikely to vary significantly over time<\/a>. It can reveal sensitive information such as health information or information about race and gender characteristics. The guidance among other things addresses key considerations for organisations when planning and implementing initiatives involving biometric technology &#8211; transparency, safeguarding data, and accuracy, including testing for biometric systems.<\/p>\n\n\n\n<p><strong>IoT data security: <\/strong>America\u2019s NIST finalized its <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2025\/08\/nist-finalizes-lightweight-cryptography-standard-protect-small-devices\">\u2018Lightweight Cryptography\u2019<\/a> Standard to Protect Small Devices. Four relevant algorithms are now ready for use to protect data created and transmitted by the Internet of Things and other electronics. The standard is built around a group of cryptographic algorithms in the <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2023\/02\/nist-selects-lightweight-cryptography-algorithms-protect-small-devices\">Ascon family, which NIST selected in 2023<\/a> as the planned basis for its lightweight cryptography standard . They require less computing power and time than more conventional cryptographic methods do, making them useful for securing data from resource-constrained devices. For more technical information on the standard, visit the NIST Lightweight Cryptography <a href=\"https:\/\/csrc.nist.gov\/projects\/lightweight-cryptography\">Project page<\/a>.&nbsp;<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_fd6543d23440a92f0eec1450e9dc6d8f\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email     <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Optus data breach in Australia<\/strong><\/h4>\n\n\n\n<p>The Australian Information Commissioner has filed civil penalty proceedings against Optus (telecommunications), following an investigation in relation to the data breach made public by Optus on 22 September 2022. The data breach involved <a href=\"https:\/\/www.oaic.gov.au\/news\/media-centre\/australian-information-commissioner-takes-civil-penalty-action-against-optus\">unauthorised access to the personal information of millions of current, former and prospective customers of Optus, and the subsequent release of some of this information on the dark web<\/a>. This included names, dates of birth, home addresses, phone numbers and email addresses, passport numbers, driver\u2019s licence numbers, Medicare card numbers, birth certificate information, marriage certificate information, and armed forces, defence force and police identification information.<\/p>\n\n\n\n<p>Based on this case the Australian regulator asks all organisations to:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>implement procedures that ensure clear ownership and responsibility over internet-facing domains<\/li>\n\n\n\n<li>ensure that requests for customers\u2019 personal information are authorised to access that information<\/li>\n\n\n\n<li>layer security controls to avoid a single point of failure<\/li>\n\n\n\n<li>implement robust security monitoring procedures to ensure any vulnerabilities are detected and that any incidents are responded to in a timely manner<\/li>\n\n\n\n<li>appropriately resource privacy and cyber security, including when outsourced to third party providers<\/li>\n\n\n\n<li>regularly review practices and systems, including actively assessing critical and sensitive infrastructure, and act on areas for improvement in a timely manner.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Voiceprint for authentication purposes<\/strong> <\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfJZ21fONh5HKx-ObyrLIGjNRcYGSMKH4lsJTtEbPjSUt8o4BJNxDY7FMjVmdELPBvc6_rnuQve9XxGaqlVXmC-boAYWEqju0s1FZD4nYehEnc9TJtnTFj_2l5c1Opqcno4zTfI?key=ljFrlDUcHoy4fWtTbATh1g\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Swiss Federal Data Protection Commissioner has examined whether <a href=\"https:\/\/www.edoeb.admin.ch\/en\/conclusion-investigation-into-voice-recognition-postfinance\">PostFinance<\/a> <a href=\"https:\/\/www.edoeb.admin.ch\/en\/conclusion-investigation-into-voice-recognition-postfinance\">(a retail banking and business client) is violating data protection regulations when using voice recognition as a means of authentication<\/a>. It concluded the investigation on 16 May with a ruling instructing PostFinance to obtain the express consent of the person concerned when creating voiceprints for voice recognition and to delete voiceprints for which no consent has been explicitly given.<\/p>\n<\/div><\/div>\n\n\n\n<p><strong>Voiceprints are a type of biometric data<\/strong>. Under data protection law, they are considered sensitive personal data if they enable the identification of an individual. Unlike a password, it cannot be recreated in case of misuse.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In other news<\/h4>\n\n\n\n<p><strong>Meta AI:<\/strong> According to the privacy advocacy group Noyb, just 7% of consumers want Meta to utilise their personal information for AI, despite the fact that over 75% of users were aware of Meta&#8217;s ambitions.&nbsp;<a href=\"https:\/\/noyb.eu\/en\/noyb-survey-only-7-users-want-meta-use-their-personal-data-ai\">Noyb has commissioned the Gallup Institute to survey 1,000 Meta users in Germany<\/a> in order to learn more.<\/p>\n\n\n\n<p>In May this year, Meta decided to begin using EU personal data to train its AI systems by just asserting that they had a &#8220;legitimate interest&#8221; under Article 6 of the GDPR. Although nearly two-thirds of the participants claim to have heard about Meta&#8217;s announcement, just 40% of Instagram or Facebook users can recall seeing the in-app message that was concealed under a notification menu, (or can recall the email notice that was sent with a subject line designed to make people ignore it).<\/p>\n\n\n\n<p>But as people age, knowledge about this issue increases significantly, while women are less inclined to give AI their data.<\/p>\n\n\n\n<p><strong>IBAN: <\/strong>The IBAN can in some cases allow a hacker to issue illegitimate direct debit orders. The hacker can also, more directly, <a href=\"https:\/\/www.cnil.fr\/fr\/fuite-de-donnees-sur-internet-et-vol-de-votre-iban-comment-vous-proteger-si-vous-etes-concerne\">usurp another person&#8217;s IBAN by communicating it when creating a direct debit mandate as part of a subscription to a service<\/a>. In order to reduce the risk of fraudulent use of your IBAN and minimise its consequences, the French regulator CNIL recommends:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Monitor your bank account transactions regularly and block your bank account if necessary. <\/li>\n\n\n\n<li>Contact your usual bank advisor if you have any doubts.<\/li>\n\n\n\n<li>Check the list of authorised creditors (eg, the beneficiaries of direct debits) in your online banking space.<\/li>\n\n\n\n<li>When receiving a pre-filled direct debit mandate, or an alleged update of it, be vigilant about the information describing the creditor.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>One click was nothing. But you gave away a lot<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXc1yqrsuNttmMUiPD69nhhM8aamnSexNQd2PEXBXnY3QZpNWaqHArrZulr4ysg8qoR8s70SszqMgw8KJGIA6eGjT3Uw9xUAduDcFxLcMWXMtsHbRyEIi3D3J1B6Y9d7YgaNuGje?key=ljFrlDUcHoy4fWtTbATh1g\" alt=\"information security\n\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>As digital technology allows for limitless information sharing with just a single click, the Latvian DVI is launching an educational public awareness campaign to encourage every digital user, but especially young people, to realise that <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/datu-valsts-inspekcija-uzsak-izglitojosu-kampanu-klikskis-bija-nieks-bet-tu-atdevi-daudz-par-personas-datu-aizsardzibu-digitalaja-vide\">personal data is a value, not an accidental footprint left on the internet<\/a>. The campaign emphasizes that seemingly harmless digital actions, such as posting your photos on social networks, participating in a free game, or clicking the &#8220;I agree&#8221; button without reading the contents of a document, can mean widespread and irreversible data transfer consequences that are not always easy to predict or reverse.<\/p>\n<\/div><\/div>\n\n\n\n<p>Similarly, Privacy International publishes a series of educational case studies to answer the question of \u201c<a href=\"https:\/\/privacyinternational.org\/news\">Why privacy matters\u201d for schoolchildren, workers, people with disabilities, protestors and even sports fans<\/a> and many others. Here are some outstanding points of the analyses:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>When surveillance creeps into classrooms and digital learning platforms, it threatens the freedom of pupils to feel safe to explore ideas, make mistakes and develop into their own unique selves.<\/li>\n\n\n\n<li>Employers are using surveillance to monitor, control, and exploit workers in ways that many may not even be aware of.<\/li>\n\n\n\n<li>The growing threat of intrusive surveillance such as AI-powered facial recognition in stadiums risks turning a vibrant cultural space into one of control and suspicion.<\/li>\n\n\n\n<li>Privacy is a universal right, but for people with disabilities, it\u2019s often compromised in the very systems designed to support them.<\/li>\n\n\n\n<li>In society, dissent &#8211; especially through protest &#8211; is vital for progress, change, and holding power accountable. Without privacy, protestors risk losing their voices, and their own safety.<\/li>\n\n\n\n<li>Migrants have the same right to a private life and to be free from intrusive surveillance as anyone else. Yet, for people on the move, this right to privacy is under constant threat.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">In case you missed it<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"774\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/social-media-6241610_1280-1024x774.png\" alt=\"\" class=\"wp-image-11075 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/social-media-6241610_1280-1024x774.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/social-media-6241610_1280-300x227.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/social-media-6241610_1280-768x580.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/social-media-6241610_1280.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Meta\u2019s \u201cstory\u201d photos:<\/strong> The Icelandic data protection regulator explains that <a href=\"https:\/\/island.is\/s\/personuvernd\/frett\/abending-personuverndar-vegna-vinnslu-meta-a-simamyndum\">Meta launched a feature that goes through photos on your phone and suggests what to post on<\/a> Facebook. The social media app automatically selects photos or videos from your phone and sends them to Meta&#8217;s servers. The photos are then processed using artificial intelligence to display post suggestions in &#8220;Story&#8221;.<\/p>\n<\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>This is done without the user having specifically uploaded the photos or videos to the social media platform for publication there. Since this may be a significant intrusion into people&#8217;s privacy, and since the regulator has received reports that people have not realised that this feature has been enabled, the regulator provided the instructions on how to disable the feature:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Open the app on your phone.<\/li>\n\n\n\n<li>Press + at the top of the screen.<\/li>\n\n\n\n<li>Tap &#8220;Story&#8221;.<\/li>\n\n\n\n<li>In the top right corner: Press the &#8220;Settings&#8221; gear.<\/li>\n\n\n\n<li>At the bottom is \u201cCamera roll settings\u201d.<\/li>\n\n\n\n<li>Turn off &#8220;Get camera roll suggestions when you&#8217;re browsing Facebook&#8221;.<\/li>\n<\/ul>\n\n\n\n<p><strong>Political advertising in the EU:<\/strong> <a href=\"https:\/\/www.aki.ee\/uudised\/meta-ja-google-peatavad-kogu-poliitilise-reklaami-pakkumise-oma-platvormidel\">Google and Meta announced that they will suspend all political advertising services in the EU<\/a> due to the application of the Political Advertising Transparency and Targeting Regulation in October 2025, the Estonian regulator reports. The implementation of the new regulation will bring a number of operational and legal requirements that are difficult to implement. As a result, Google has decided to suspend all political advertising services, including on YouTube, until there is greater clarity on the implementation of the regulation. However, Meta believes that the implementation of the new regulation will make the current transparency and targeting systems too complex and ineffective, significantly reducing the ability of advertisers to reach the electorate.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How is data protection related to information security?&nbsp; The goal of information security is to protect an organisation&#8217;s business processes. This means responsibility for the security of the entire operating system and the ability to resist any activities that threaten the availability, authenticity, integrity, and confidentiality of data processed in the system or the services [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":11077,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94,88],"tags":[51,252,129,122,58,200],"class_list":["post-11074","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","category-gdpr","tag-artificial-intelligence","tag-biometrics","tag-consumer-data-protection","tag-data-subject-access-requests","tag-gdpr-compliance","tag-voiceprints"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png",1280,1280,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-300x300.png",300,300,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-768x768.png",640,640,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-1024x1024.png",640,640,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png",1280,1280,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png",1280,1280,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-200x200.png",200,200,true]},"post_excerpt_stackable":"<p>How is data protection related to information security?&nbsp; The goal of information security is to protect an organisation&#8217;s business processes. This means responsibility for the security of the entire operating system and the ability to resist any activities that threaten the availability, authenticity, integrity, and confidentiality of data processed in the system or the services provided and accessed through the system, according to the Estonian data protection regulator. The information assets include all IT resources \u2013 hardware, software, various data communication devices, etc. However, people working in an organisation and customers can also be considered information assets. Therefore, it can&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png",1280,1280,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-300x300.png",300,300,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-768x768.png",640,640,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-1024x1024.png",640,640,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png",1280,1280,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png",1280,1280,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280-200x200.png",200,200,true]},"post_excerpt_stackable_v2":"<p>How is data protection related to information security?&nbsp; The goal of information security is to protect an organisation&#8217;s business processes. This means responsibility for the security of the entire operating system and the ability to resist any activities that threaten the availability, authenticity, integrity, and confidentiality of data processed in the system or the services provided and accessed through the system, according to the Estonian data protection regulator. The information assets include all IT resources \u2013 hardware, software, various data communication devices, etc. However, people working in an organisation and customers can also be considered information assets. Therefore, it can&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d - Estonian regulator - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the important data-related stories: Data protection says what should be done, information security says how we do it\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d - Estonian regulator - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the important data-related stories: Data protection says what should be done, information security says how we do it\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-18T14:35:54+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-08-19T09:07:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d &#8211; Estonian regulator\",\"datePublished\":\"2025-08-18T14:35:54+00:00\",\"dateModified\":\"2025-08-19T09:07:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/\"},\"wordCount\":2829,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/universal-access-6602642_1280.png\",\"keywords\":[\"Artificial Intelligence\",\"Biometrics\",\"consumer data protection\",\"data subject access requests\",\"GDPR Compliance\",\"voiceprints\"],\"articleSection\":[\"Data Protection Digest\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/\",\"name\":\"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d - Estonian regulator - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/universal-access-6602642_1280.png\",\"datePublished\":\"2025-08-18T14:35:54+00:00\",\"dateModified\":\"2025-08-19T09:07:52+00:00\",\"description\":\"TechGDPR\u2019s review of the important data-related stories: Data protection says what should be done, information security says how we do it\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/universal-access-6602642_1280.png\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/universal-access-6602642_1280.png\",\"width\":1280,\"height\":1280,\"caption\":\"information security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d &#8211; Estonian regulator\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d - Estonian regulator - TechGDPR","description":"TechGDPR\u2019s review of the important data-related stories: Data protection says what should be done, information security says how we do it","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d - Estonian regulator - TechGDPR","og_description":"TechGDPR\u2019s review of the important data-related stories: Data protection says what should be done, information security says how we do it","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/","og_site_name":"TechGDPR","article_published_time":"2025-08-18T14:35:54+00:00","article_modified_time":"2025-08-19T09:07:52+00:00","og_image":[{"width":1280,"height":1280,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png","type":"image\/png"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d &#8211; Estonian regulator","datePublished":"2025-08-18T14:35:54+00:00","dateModified":"2025-08-19T09:07:52+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/"},"wordCount":2829,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png","keywords":["Artificial Intelligence","Biometrics","consumer data protection","data subject access requests","GDPR Compliance","voiceprints"],"articleSection":["Data Protection Digest","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/","name":"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d - Estonian regulator - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png","datePublished":"2025-08-18T14:35:54+00:00","dateModified":"2025-08-19T09:07:52+00:00","description":"TechGDPR\u2019s review of the important data-related stories: Data protection says what should be done, information security says how we do it","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/universal-access-6602642_1280.png","width":1280,"height":1280,"caption":"information security"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18082025-data-protection-says-what-should-be-done-information-security-says-how-we-do-it\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 2-17 Aug 2025: \u201cData protection says what should be done, information security says how we do it\u201d &#8211; Estonian regulator"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11074","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=11074"}],"version-history":[{"count":37,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11074\/revisions"}],"predecessor-version":[{"id":11116,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11074\/revisions\/11116"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/11077"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=11074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=11074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=11074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}