{"id":8040,"date":"2024-02-19T11:51:24","date_gmt":"2024-02-19T10:51:24","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=8040"},"modified":"2025-06-11T14:04:47","modified_gmt":"2025-06-11T12:04:47","slug":"data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/","title":{"rendered":"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won&#8217;t help your business"},"content":{"rendered":"\n<p><em>In this issue, you will find that America\u2019s FTC is warning against retroactively changing terms of service or privacy policy. Palantir running the NHS\u2019s new data platform in the UK, and envisaged changes to the EU GDPR enforcement framework and new dispute resolution mechanisms are also in focus.<\/em><\/p>\n\n\n\n<p><em><a href=\"#newslettersignup\">Sign up to receive our fortnightly digest via email.<\/a><\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Terms of Service and User Privacy<\/h4>\n\n\n\n<p>America\u2019s FTC warns AI developers and other companies that <a href=\"https:\/\/www.ftc.gov\/policy\/advocacy-research\/tech-at-ftc\/2024\/02\/ai-other-companies-quietly-changing-your-terms-service-could-be-unfair-or-deceptive\">quietly changing terms of service could be unfair or deceptive<\/a>. While businesses creating AI products have strong financial incentives to utilize user data as fuel for their systems, they also have established policies in place to safeguard users&#8217; privacy. A business that collects user data based on one set of privacy commitments cannot then unilaterally renege on those commitments after collecting users\u2019 data. Some companies may attempt to make these changes and inform users covertly by making retroactive amendments to their terms of service or privacy policy, (eg, to use that data for AI training).&nbsp;<\/p>\n\n\n\n<p>Last summer, the FTC alleged that a genetic testing company violated the law when the company changed its privacy policy to<a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/06\/ftc-says-genetic-testing-company-1health-failed-protect-privacy-security-dna-data-unfairly-changed\"> retroactively expand the kinds of third parties with which it could share consumers\u2019 sensitive data<\/a>, adding supermarket chains and nutrition and supplement manufacturers, without notifying consumers who had previously shared personal data, or obtaining their consent. Additionally, it did not encrypt that data, restrict access to it, log or monitor access to it, or inventory it, according to the complaints. The company stored it in publicly accessible \u201cbuckets\u201d on a cloud storage service with thousands of health reports about consumers and raw genetic data, sometimes accompanied by a first name, despite promising users its security practices would exceed industry-standard security practices.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Other official guidance<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:31% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/people-4009327_1280-1024x682.png\" alt=\"\" class=\"wp-image-8058 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/people-4009327_1280-1024x682.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/people-4009327_1280-300x200.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/people-4009327_1280-768x512.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/people-4009327_1280.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Employment data: <\/strong>The Italian privacy regulator launched the <a href=\"https:\/\/www.dataguidance.com\/news\/italy-garante-approves-code-conduct-employers\">Code of Conduct for employment<\/a> agencies. The agencies that adhere to the code undertake to process only data strictly necessary for the establishment of the employment relationship and must therefore not carry out investigations into jobseeker\u2019s political, religious or trade union opinions or carry out pre-selections based on information regarding marital status, pregnancy, disability, even if candidates have given their consent.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>Agencies must not obtain information by consulting social profiles intended for interpersonal communication. Online information can be collected only if made available on professional social channels. Furthermore, employment agencies will not be able to acquire the candidate&#8217;s professional references from previous employers and communicate them to their clients, without &#8220;prior explicit authorization from the candidate&#8221;.<\/p>\n\n\n\n<p><strong>Camera systems: <\/strong>The Czech data protection authority has published a new <a href=\"https:\/\/uoou.gov.cz\/novinky\/vse\/nova-metodika-uradu-ke-kamerovym-systemum\">methodology for the design and operation of camera systems<\/a>, (in Czech). The methodology applies to camera systems, (including security cameras), that record as well as camera systems in online mode, minimum technical and organisational measures for them, and use cases. The methodology is not a legally binding document and it remains the duty of personal data administrators to always proceed following the GDPR and <a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/our-documents\/guidelines\/guidelines-32019-processing-personal-data-through-video_en\">EDPB Guidelines No. 3\/2019<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">New procedures for GDPR enforcement<\/h4>\n\n\n\n<p>MEPs have adopted a draft position laying down additional procedural rules for enforcing the GDPR. It deals with <a href=\"https:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20240212IPR17631\/new-measures-to-strengthen-the-cross-border-enforcement-of-the-gdpr\">cooperation and dispute resolution mechanisms<\/a> of the GDPR and introduces deadlines for cross-border procedures and disputes. Concerning <a href=\"https:\/\/edpb.europa.eu\/system\/files\/2022-06\/edpb_guidelines_202206_on_the_practical_implementation_of_amicable_settlements_en.pdf\">amicable settlements<\/a>, such settlements should require the parties&#8217; explicit consent, and should not prevent a supervisory authority from starting an own-initiative investigation into the matter. The MEP&#8217;s position also ensures that all parties to complaint procedures have the right to effective judicial remedies, for example when the regulator does not take necessary actions or comply with deadlines.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Digital Services Act is now fully applicable&nbsp;<\/h4>\n\n\n\n<p>The DSA has applied to online platforms and search engines with more than 45 million users in the EU since 25 August 2023. <a href=\"https:\/\/entreprendre.service-public.fr\/actualites\/A16089?lang=en\">From 17 February, it applies to smaller platforms and online intermediaries<\/a>, (goods, content or services), on the European market. Its main goal is to prevent illegal and harmful activities online and the spread of disinformation. For instance, if you complain about what <a href=\"https:\/\/tietosuoja.fi\/-\/digipalveluiden-uudet-saannokset-voimaan-nain-kayttajan-asema-paranee\">you suspect is illegal content, the service provider must handle the matter and inform you<\/a> of its solution.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/dsa-cooperation\">Compliance will be supervised by the specialised agencies<\/a> in the Member States, and certain obligations by consumer protection and data protection authorities. To avoid disproportionate constraints, small companies, (with less than 50 employees and an annual turnover of less than EUR 10 million), and micro-enterprises are exempted from the application of various measures, (transparency reports, internal complaints handling system, etc.). More details on the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/dsa-enforcement\">enforcement framework under the DSA are here<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<p><strong>Main establishment in the EU:<\/strong> The EDPB clarified the notion of the main establishment under the GDPR rules. A <a href=\"https:\/\/edpb.europa.eu\/news\/news\/2024\/edpb-clarifies-notion-main-establishment-and-calls-eu-legislators-make-sure-csam_en\">controller\u2019s \u201cplace of central administration\u201d in the EU<\/a> can be considered as a main establishment under Art. 4(16)(a) GDPR only if:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>it makes the decisions on the purposes and means of the processing of personal data and,&nbsp;<\/li>\n\n\n\n<li>it has the power to have such decisions implemented.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Furthermore, the One-Stop-Shop mechanism can only apply if there is evidence that one of the establishments of the controller in the Union takes decisions on the purposes and means for the relevant processing operations and has the power to have these decisions implemented. This means that, when the decisions on the purposes and means of the processing are taken outside of the EU, there is considered to be no main establishment of the controller in the Union, and therefore the One-Stop-Shop should not apply.<\/p>\n\n\n\n<p><strong>CPRA enforcement:<\/strong> California&#8217;s Third District Court of Appeal held that <a href=\"https:\/\/cppa.ca.gov\/announcements\/2024\/20240209.html\">the California Privacy Protection Agency\u2019s authority to enforce its amended privacy regulations should have been effective on July 1, 2023<\/a>. The decision restores the CPPA\u2019s authority and overturns a lower court ruling. The agency has been vigorously enforcing the statutory rights approved by Californians &#8211; Proposition 24, the California Privacy Rights Act of 2020 (CPRA). Some of the new and amended regulations implementing the CPRA, which largely define and clarify how businesses must honour those rights, were previously deemed unenforceable by the lower court.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Video gaming and children\u2019s data<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:31% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-us.googleusercontent.com\/qlM1TqppYbPZN4U9CkwNDI5yQbbsEcp14EyL8rgu-lOwkMfpIdCoJ3xvvFUzggpact-QeT7WFdsesJW9QzP4lqOKlfMisSSt36xEhwlbqAhmNjFj6zMj4lduh2rMamsIyucalJKBCgx7PPEOkJSTg_U\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The ICO has carried out an age-appropriate design code audit of Gameforge\u2019s processing of UK children\u2019s data. The majority of their games are rated as suitable for children aged 0-12 years. Gameforge does not collect any user data to confirm their ages or identify child users, and subsequently has chosen to apply safeguards to all users by implementing pseudonymisation of all user account data, and not implementing higher risk processing activities such as location tracking or profiling. Gameforge does not use personal data to promote or market third-party products or services, and Gameforge&#8217;s online services do not include any third-party advertising.<\/p>\n<\/div><\/div>\n\n\n\n<p>As notably good practice, the ICO underlined the high level of qualifications and involvement of the data protection team. In particular, Gameforge has made two DPO-certified members key signatories to the company accounts and new\/changed contracts. However, opportunities for improvement were also identified, such as a clearer privacy policy, and DPIA that records consultation and feedback\/approval with key stakeholders. An assessment also should be undertaken to consider and document the potential ages of users, which can be achieved non-intrusively by using anonymous or aggregated data such as market research.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Cookie-banners supervision<\/h4>\n\n\n\n<p>The Dutch regulator promised to intensify the checks of websites and explained, one more time, <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/themas\/internet-slimme-apparaten\/cookies\/heldere-en-misleidende-cookiebanners\">how organisations should set up cookie banners<\/a> to properly request permission:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>to provide information in clear text about the purpose;<\/li>\n\n\n\n<li>not to automatically enable checkboxes;<\/li>\n\n\n\n<li>give all choices in the first layer, (don&#8217;t hide certain choices and don&#8217;t make someone make extra clicks);<\/li>\n\n\n\n<li>not to use a discreet link in the text;<\/li>\n\n\n\n<li>be clear about withdrawing consent;<\/li>\n\n\n\n<li>carefully choose the legal basis, (do not confuse consent with legitimate interest).<\/li>\n<\/ul>\n\n\n\n<p>The Bavarian data protection authority meanwhile <a href=\"https:\/\/netzpolitik.org\/2024\/bayern-ueberprueft-cookie-banner-vieler-seiten-weiterhin-rechtswidrig\/\">checked the cookie banners of hundreds of websites and apps<\/a> and found numerous violations. Many operators, (around 350 websites), now have to change their pages. The regulator has successfully developed a tool which makes it possible to automatically check websites to see whether, in addition to the \u201cAccept All\u201d option, there is also an equivalent option for not granting consent. The <a href=\"https:\/\/www.lda.bayern.de\/media\/pm\/pm2024_02.pdf\">test is initially based on the use of a very common consent management platform<\/a>, (CMP), but will be expanded to include other CMP providers and thus an even larger number of websites in future iterations.<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_b5586cdc4cfe66dff83ed41eb2b953d6\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Enforcement decisions<\/h4>\n\n\n\n<p><strong>Data storage periods: <\/strong>The French CNIL fined the company which publishes the pap.fr website, allowing individuals to view and publish real estate ads, 100,000 euros. The <a href=\"https:\/\/www.cnil.fr\/fr\/duree-de-conservation-et-securite-des-donnees-la-cnil-sanctionne-la-societe-pap-dune-amende-de-100\">company had defined a retention period of ten years for the customer accounts using paid services on the site<\/a>, against the consumer code on which it relied. The company informed individuals through an incomplete and unclear privacy policy. The password complexity rule was insufficiently robust and passwords and related data were stored unencrypted. All data relating to inactive user accounts was kept unsorted.&nbsp;<\/p>\n\n\n\n<p><strong>Online dating site: <\/strong>The Italian data protection authority <a href=\"https:\/\/www.garanteprivacy.it\/garante\/doc.jsp?ID=9978568\">has fined<\/a> the manager of a well-known <a href=\"https:\/\/www.garanteprivacy.it\/temi\/internet-e-nuove-tecnologie\/dating-online\">online dating<\/a> site 200,000 euros for violating the personal data of about 1 million members. Registration on the platform, which has about 5 million members worldwide required the insertion of numerous data, (meeting interest, country, region, city of residence, date of birth, e-mail), and photos, which customers uploaded within the public profile or in the reserved area, without being provided with adequate information on the use that would be made of that data. The information also did not contain any indication of the possibility for data subjects to exercise their rights provided for by privacy legislation.\u00a0<\/p>\n\n\n\n<p>The owner of the site did not have a specific privacy policy regarding the storage of the data processed, limiting itself to randomly proceeding with the deletion of accounts that are no longer active and the information contained, as well as unsuccessful registration requests. Finally, although the company was required to do so, it had not drawn up a register of processing activities, had not appointed a DPO, nor had it prepared an impact assessment (DPIA).&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Viamedis and Almerys <\/strong>data breach<\/h4>\n\n\n\n<p> The French CNIL is conducting investigations into a data breach which has affected Viamedis and Almerys, operators managing third-party payment for numerous complementary health insurance and mutual insurance companies. More than <a href=\"https:\/\/www.cnil.fr\/fr\/violation-de-donnees-de-deux-operateurs-de-tiers-payant-la-cnil-ouvre-une-enquete-et-rappelle-aux\">33 million people are affected<\/a>. The data concerned civil status, date of birth and social security number, and the name of the health insurer. Data such as banking information, medical data, health reimbursements, postal addresses, telephone numbers and emails are not be affected by the breach.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Shoplifter identity<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/hangers-1850082_1280-1024x682.jpg\" alt=\"\" class=\"wp-image-8061 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/hangers-1850082_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/hangers-1850082_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/hangers-1850082_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/hangers-1850082_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Dutch data protection authority has granted 500 <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/ap-verleent-500e-vergunning-aan-winkeliers-die-elkaar-waarschuwen-voor-winkeldieven\">permits for a collective shopping ban<\/a>. Shopkeepers with such a permit can warn each other in a defined area about shoplifters and people who cause nuisance, sharing their names and photos. Shopkeepers may only share such a &#8216;blacklist&#8217; with each other under strict conditions. For example, someone from the police, the municipality or the public prosecution service must always be involved.<\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Big Data<\/h4>\n\n\n\n<p><strong>UK health care data: <\/strong>The Good Law Project NGO raises concerns about the lack of transparency in the contract allowing Palantir to run the NHS\u2019s new system \u2013 the Federated Data Platform. The organisation has now taken <a href=\"https:\/\/goodlawproject.org\/were-taking-legal-action-to-uncover-palantirs-blanked-out-contract\/?fbclid=IwAR3QuyJB2efaXycDTbNARQUgaG0eq9u-fTN87BecMpqjaZJSIT3KQgDsMN0\">legal action to challenge the NHS<\/a>\u2019s data governance. Despite the massive scale of redactions in Palantir\u2019s 500+ page contract, the NGO insists no reasons for the secrecy have been given by the public bodies.<em> <\/em>The NHS has also signed a contract with the <a href=\"https:\/\/goodlawproject.org\/were-taking-legal-action-to-uncover-palantirs-blanked-out-contract\/?fbclid=IwAR3QuyJB2efaXycDTbNARQUgaG0eq9u-fTN87BecMpqjaZJSIT3KQgDsMN0\">biotech IQVIA, to provide \u201cPrivacy Enhancing Technology\u201d<\/a> for the platform. Around three-quarters of the contract is also completely redacted, including a section on personal data protection.&nbsp;<\/p>\n\n\n\n<p><strong>Pupil surveillance: <\/strong>Privacy International reports that <a href=\"https:\/\/privacyinternational.org\/examples\/5256\/schools-install-toilet-sensors-actively-listen-pupils\">some UK schools have bought and installed sensors in toilets that &#8216;actively listen&#8217; to pupils<\/a>&#8216; conversations to try to detect keywords spoken by pupils. Such sensors do not record or save any conversations but send alerts to staff when triggered. At the same time, some schools are also <a href=\"https:\/\/schoolsweek.co.uk\/schools-install-toilet-sensors-that-actively-listen-to-pupils\/\">pairing them with surveillance cameras<\/a>, so when activated by a vaping sensor they capture students leaving bathrooms.&nbsp;<\/p>\n\n\n\n<p><strong>Ulez fines:<\/strong> Italy is investigating the case of <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/9982333\">Italian police allegedly accessing thousands of EU drivers\u2019 data<\/a> and sharing it with firms collecting fines on behalf of Transport for London, (TfL). Some other Member States have also claimed that a police department that has not been named has abused its authority by providing personal information about EU drivers to Euro Parking Collections. TfL uses this company to levy fines to enforce low and ultra-low emission zones, (Ulez). <a href=\"https:\/\/www.theguardian.com\/environment\/2024\/feb\/08\/ulez-fines-scandal-italian-police-illegally-accessed-thousands-of-eu-drivers-data?fbclid=IwAR3iIT7ej6E-fGeZyySRR9JsguPCDUzHzmsMo9xZuP3Q-gQJxOFZh46DFMw\">Due to national regulations permitting the UK to access EU individuals&#8217; data only for criminal offenses<\/a> and the fact that breaking Ulez guidelines is considered a civil violation, it is believed that the fines have been unlawfully levied since Brexit.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this issue, you will find that America\u2019s FTC is warning against retroactively changing terms of service or privacy policy. Palantir running the NHS\u2019s new data platform in the UK, and envisaged changes to the EU GDPR enforcement framework and new dispute resolution mechanisms are also in focus. Sign up to receive our fortnightly digest [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":8043,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94,88],"tags":[100,122,98,165,58,258,266],"class_list":["post-8040","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","category-gdpr","tag-cookies","tag-data-subject-access-requests","tag-direct-marketing","tag-employment-data","tag-gdpr-compliance","tag-health-related-data","tag-minors-data"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png",1280,905,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-300x212.png",300,212,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-768x543.png",640,453,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-1024x724.png",640,453,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png",1280,905,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png",1280,905,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-200x200.png",200,200,true]},"post_excerpt_stackable":"<p>In this issue, you will find that America\u2019s FTC is warning against retroactively changing terms of service or privacy policy. Palantir running the NHS\u2019s new data platform in the UK, and envisaged changes to the EU GDPR enforcement framework and new dispute resolution mechanisms are also in focus. Sign up to receive our fortnightly digest via email. Terms of Service and User Privacy America\u2019s FTC warns AI developers and other companies that quietly changing terms of service could be unfair or deceptive. While businesses creating AI products have strong financial incentives to utilize user data as fuel for their systems,&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png",1280,905,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-300x212.png",300,212,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-768x543.png",640,453,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-1024x724.png",640,453,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png",1280,905,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png",1280,905,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280-200x200.png",200,200,true]},"post_excerpt_stackable_v2":"<p>In this issue, you will find that America\u2019s FTC is warning against retroactively changing terms of service or privacy policy. Palantir running the NHS\u2019s new data platform in the UK, and envisaged changes to the EU GDPR enforcement framework and new dispute resolution mechanisms are also in focus. Sign up to receive our fortnightly digest via email. Terms of Service and User Privacy America\u2019s FTC warns AI developers and other companies that quietly changing terms of service could be unfair or deceptive. While businesses creating AI products have strong financial incentives to utilize user data as fuel for their systems,&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won&#039;t help your business - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data privacy stories: sneakily changing terms of service and privacy policy won&#039;t help your business\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won&#039;t help your business - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data privacy stories: sneakily changing terms of service and privacy policy won&#039;t help your business\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-02-19T10:51:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-11T12:04:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"905\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won&#8217;t help your business\",\"datePublished\":\"2024-02-19T10:51:24+00:00\",\"dateModified\":\"2025-06-11T12:04:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/\"},\"wordCount\":2146,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/mobile-app-development-company-8379091_1280.png\",\"keywords\":[\"cookies\",\"data subject access requests\",\"direct marketing\",\"employment data\",\"GDPR Compliance\",\"health-related data\",\"minors data\"],\"articleSection\":[\"Data Protection Digest\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/\",\"name\":\"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won't help your business - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/mobile-app-development-company-8379091_1280.png\",\"datePublished\":\"2024-02-19T10:51:24+00:00\",\"dateModified\":\"2025-06-11T12:04:47+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data privacy stories: sneakily changing terms of service and privacy policy won't help your business\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/mobile-app-development-company-8379091_1280.png\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/mobile-app-development-company-8379091_1280.png\",\"width\":1280,\"height\":905,\"caption\":\"terms of service\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won&#8217;t help your business\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won't help your business - TechGDPR","description":"TechGDPR\u2019s review of the most important data privacy stories: sneakily changing terms of service and privacy policy won't help your business","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won't help your business - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data privacy stories: sneakily changing terms of service and privacy policy won't help your business","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/","og_site_name":"TechGDPR","article_published_time":"2024-02-19T10:51:24+00:00","article_modified_time":"2025-06-11T12:04:47+00:00","og_image":[{"width":1280,"height":905,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png","type":"image\/png"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won&#8217;t help your business","datePublished":"2024-02-19T10:51:24+00:00","dateModified":"2025-06-11T12:04:47+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/"},"wordCount":2146,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png","keywords":["cookies","data subject access requests","direct marketing","employment data","GDPR Compliance","health-related data","minors data"],"articleSection":["Data Protection Digest","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/","name":"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won't help your business - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png","datePublished":"2024-02-19T10:51:24+00:00","dateModified":"2025-06-11T12:04:47+00:00","description":"TechGDPR\u2019s review of the most important data privacy stories: sneakily changing terms of service and privacy policy won't help your business","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/02\/mobile-app-development-company-8379091_1280.png","width":1280,"height":905,"caption":"terms of service"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19022024-sneakily-changing-terms-of-service-and-privacy-policy-wont-help-your-business\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 3-16 Feb 2024: Sneakily changing terms of service and privacy policy won&#8217;t help your business"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=8040"}],"version-history":[{"count":24,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8040\/revisions"}],"predecessor-version":[{"id":10733,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8040\/revisions\/10733"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/8043"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=8040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=8040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=8040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}