{"id":8198,"date":"2024-03-05T11:51:50","date_gmt":"2024-03-05T10:51:50","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=8198"},"modified":"2025-02-03T09:36:02","modified_gmt":"2025-02-03T08:36:02","slug":"data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/","title":{"rendered":"Data protection digest 18 Feb &#8211; 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0"},"content":{"rendered":"\n<p><em>This issue highlights how web browsing data, non-anonymised according to America\u2019s FTC, was sold worldwide in the Avast\/Jumpshot case, the EDPB\u2019s new enforcement action on the right of access, cloud outsourcing in the banking sector, the NIST\u2019s new cybersecurity framework for all organisations, and federated learning analysis.<\/em><\/p>\n\n\n\n<p><a href=\"#newslettersignup\"><em>Stay tuned! Sign up to receive our fortnightly digest via email.<\/em><\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Web browsing data for sale<\/h4>\n\n\n\n<p>The UK software provider Avast will have to pay 16.5 million dollars to the US Federal Trade Commission, and the business will not be allowed to sell or license any web browsing data for advertising purposes. Avast Limited, a UK-based firm, <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2024\/02\/ftc-order-will-ban-avast-selling-browsing-data-advertising-purposes-require-it-pay-165-million-over?utm_source=govdelivery\">obtained customer surfing data unjustly through its antivirus software and browser extensions, retained it indefinitely, and sold it<\/a> without providing consumers with sufficient notice or asking for their consent. The company also did this through its Czech subsidiary.&nbsp;<\/p>\n\n\n\n<p>Following its acquisition of rival antivirus software supplier Jumpshot, Avast renamed the business as an analytics firm. Jumpshot sold surfing data that Avast had gathered from users between 2014 and 2020 to a range of customers, including marketing, advertising, and data analytics firms as well as data brokers. The business said that before sending the data to its clients, it eliminated identifying information using an algorithm.&nbsp;<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280-1024x682.jpg\" alt=\"web browsing data\" class=\"wp-image-8203 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>However, according to the FTC, the <a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/02\/ftc-says-avast-promised-privacy-pirated-consumers-data-treasure\">business did not adequately anonymise user web browsing data that it sold through a variety of products<\/a> in non-aggregated form. The FTC says, the business did not prohibit some of its data purchasers from using Jumpshot&#8217;s data to re-identify Avast users. For instance, Jumpshot allegedly signed a deal with advertising giant Omnicom for a supply of an &#8220;All Clicks Feed&#8221; for 50% of its clients in the US, UK, Mexico, Australia, Canada, and Germany.\u00a0<\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Americans&#8217; sensitive data<\/h4>\n\n\n\n<p>The US seems to have increased regulations on restricted cross-border data transfers due to national security concerns.&nbsp;<\/p>\n\n\n\n<p>President Biden issued an Executive Order to protect Americans\u2019 sensitive personal data. It will prevent the large-scale transfer of America\u2019s sensitive and government-related data to countries of concern, (reportedly they are China, Cuba, Iran, North Korea, Russia and Venezuela), and prohibit commercial data brokers and other companies from selling biometrics, healthcare, geolocation, financial and other sensitive data to countries of concern, or entities controlled by those governments, intelligence services and militaries.&nbsp;<\/p>\n\n\n\n<p>The US Justice Department\u2019s National Security Division has already published an Advance Notice of Proposed Rulemaking to provide transparency and clarity about the intended scope of the program. It would include six defined categories of bulk US sensitive data &#8211; <strong>US persons\u2019 covered personal identifiers, personal financial data, health, precise geolocation data, biometric identifiers, human genomic data<\/strong>, and combinations of those data. The security requirements for certain data classes of transactions would include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>basic organisational cybersecurity posture,<\/li>\n\n\n\n<li>measures against unauthorised disclosure,&nbsp;<\/li>\n\n\n\n<li>data minimisation and masking,<\/li>\n\n\n\n<li>use of privacy-preserving technologies,<\/li>\n\n\n\n<li>compliance requirements and audits.<\/li>\n<\/ul>\n\n\n\n<p>The Department of Justice is also considering identifying <a href=\"https:\/\/www.justice.gov\/opa\/media\/1340216\/dl\">three classes of restricted data transactions: a) vendor agreements, (including for technology services and cloud services), b) employment agreements, and c) investment agreements.<\/a> Nonetheless, the order program is without prejudice to the free flow of data necessary for substantial consumer, economic, scientific, and trade relationships that the US has with other countries.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Other official guidance<\/h4>\n\n\n\n<p><strong>The EDPB\u2019s new enforcement action:<\/strong> 31 data protection authorities across the EEA, (DPAs), including <a href=\"https:\/\/datenschutzkonferenz-online.de\/media\/pm\/2024-02-28_DSK-PM_CEF-2024-Auskunftsrecht.pdf\">7 German state-level regulators<\/a>, will participate in the 2024 enforcement action, (mixture of surveys and formal investigations), on <a href=\"https:\/\/edpb.europa.eu\/news\/news\/2024\/cef-2024-launch-coordinated-enforcement-right-access_en\">implementing the right of access<\/a>. It is one of the most frequently exercised data protection rights, which DPAs receive many complaints about. In addition, it often enables the exercise of other data protection rights, such as the right to rectification and erasure. To understand how organisations must respond to access requests from individuals, see the <a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/our-documents\/guidelines\/guidelines-012022-data-subject-rights-right-access_en\">EDPB\u2019s latest guidelines on the right of access<\/a>.&nbsp;<\/p>\n\n\n\n<p><strong>Generative AI and data protection: <\/strong>In the UK,<strong> <\/strong>the House of Lords Communications and Digital Committee has published a report on large language models, (LLMs). These <a href=\"https:\/\/publications.parliament.uk\/pa\/ld5804\/ldselect\/ldcomm\/54\/5402.htm\">may have personal data in their training sets, drawn from proprietary sources<\/a> or information online. Safeguards to prevent inappropriate regurgitation are being developed but are not robust. Data protection in healthcare attracts particular scrutiny as some firms are already using the technology on NHS data, which may yield major benefits.&nbsp;<\/p>\n\n\n\n<p>But equally, <a href=\"https:\/\/publications.parliament.uk\/pa\/ld5804\/ldselect\/ldcomm\/54\/5408.htm#_idTextAnchor083\">models cannot easily unlearn data, including protected personal data<\/a>. There may be concerns about these businesses being acquired by large overseas corporations involved in, for example, insurance or credit scoring. Clear guidance is needed on how the data protection law applies to the complexity of LLM processes, including the extent to which individuals can seek redress if a model has already been trained on their data and released. Also, data protection provisions have to be embedded in licensing terms.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Consent principle<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/signing-6598540_1280-1024x682.jpg\" alt=\"\" class=\"wp-image-8199 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/signing-6598540_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/signing-6598540_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/signing-6598540_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/signing-6598540_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><a href=\"https:\/\/www.datatilsynet.dk\/borger\/samtykke\">It is not always necessary for a company or an authority to obtain your consent<\/a> before they can handle your data explains the Danish data protection authority. This is because consent is only one of several legal bases when it comes to the handling of your data. Storage of your information shall cease when you withdraw your consent, but only the information that is handled or processed based on consent.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>Information where the legal basis is someone else, for example in the case of a commercial contract or employment relationship, can continue to be handled or stored. It is also not needed if you, the data subject, are unable to give consent, for example, to a healthcare facility due to a serious illness. Public authorities can also process your data for specific tasks, such as handling your tax declarations. Private companies might have some legitimate reasons too, (such as for maintaining user services), but they should not violate your interests or rights.&nbsp;<\/p>\n\n\n\n<p>Finally, <a href=\"https:\/\/www.datatilsynet.dk\/borger\/samtykke\">a revocation of consent does not have a retroactive effect<\/a>, and the revocation therefore does not affect the handling of information that took place before.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">&nbsp;Rise in outsourcing contracts in the banking sector<\/h4>\n\n\n\n<p>The European Central Bank urges supervised institutions to tackle <a href=\"https:\/\/www.bankingsupervision.europa.eu\/press\/publications\/newsletter\/2024\/html\/ssm.nl240221.en.html\">vulnerabilities stemming from their increasing operational reliance on third-party providers<\/a>. Most banks outsource certain services to take advantage of lower costs, more flexibility and greater efficiency. Considering the relatively stringent data protection regulations in the EU, it is noteworthy that <a href=\"https:\/\/www.bankingsupervision.europa.eu\/ecb\/pub\/pdf\/ssm.outsourcing_horizontal_analysis_202402~2b85022be5.en.pdf\">personal data processing is included in 70% of outsourcing contracts<\/a>, and over 70 major banks contract these vital services out to companies with headquarters located outside the EU, (eg, cloud services in the US, the UK, and Switzerland).&nbsp;<\/p>\n\n\n\n<p>The ECB discovered that over 10% of contracts concerning essential tasks do not adhere to the applicable requirements. Furthermore, 20% of these non-compliant contracts have not had a rigorous risk assessment during the past three years, and 60% have not undergone an audit.<\/p>\n\n\n\n<p>Starting in 2025, the <a href=\"https:\/\/www.eiopa.europa.eu\/digital-operational-resilience-act-dora_en\">Digital Operational Resilience Act<\/a> will go into effect and offer further tools for monitoring important IT service providers, particularly those that ensure the operational resilience of financial institutions.<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_43c33278c59ce5f6229b9b221387f157\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Illicit marketing<\/h4>\n\n\n\n<p>The Italian privacy regulator imposed a <a href=\"https:\/\/www.garanteprivacy.it\/garante\/doc.jsp?ID=9988710\">fine of over 79 million euros on Enel Energia<\/a> for serious shortcomings in the processing of personal data of numerous users in the electricity and gas sector, carried out for telemarketing purposes. The case originated from a previous investigation which involved a 1,8 million euro privacy fine on four companies and confiscated databases used for illicit activities. It emerged that Enel Energia had acquired 978 contracts from the above companies, even though these did not belong to the energy company&#8217;s sales network.&nbsp;<\/p>\n\n\n\n<p>Furthermore, the information systems used for customer management and service activation by the company showed serious security shortcomings. Enel failed to put in place all the necessary measures to prevent the unlawful activities of unauthorised actors who for years fueled an <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/9988921\">illicit business carried out through nuisance calls, service promotions, and the signing of contracts with no real economic benefits for customers<\/a>. Over time it involved the activation of at least 9,300 contracts.<\/p>\n\n\n\n<div class=\"wp-block-media-text has-media-on-the-right is-stacked-on-mobile\" style=\"grid-template-columns:auto 20%\"><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>Meanwhile, in California, a company will pay a 375,000 dollar civil penalty after it violated multiple consumer privacy laws. DoorDash is a San Francisco-based company that operates a website and mobile app through which consumers may order food delivery. To reach new customers, DoorDash participated in marketing cooperatives and <a href=\"https:\/\/oag.ca.gov\/news\/press-releases\/attorney-general-bonta-announces-settlement-doordash-investigation-finds-company\">disclosed consumers&#8217; personal information as part of its membership without providing notice or an opportunity to opt-out<\/a>. The other businesses participating in the cooperative also gained the opportunity to market to DoorDash customers.&nbsp;<\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"791\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/info-908889_1280-791x1024.png\" alt=\"web browsing data\n\" class=\"wp-image-8215 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/info-908889_1280-791x1024.png 791w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/info-908889_1280-232x300.png 232w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/info-908889_1280-768x994.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/info-908889_1280.png 989w\" sizes=\"(max-width: 791px) 100vw, 791px\" \/><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Data brokerage<\/h4>\n\n\n\n<p>Belgium\u2019s data protection regulator recently fined Black Tiger Belgium, (formerly Bisnode Belgium), a company specialising in big data and data management, a total of 174,640 euros. At the time when the complaints were lodged, Bisnode Belgium operated a consumer database and a company database through which Bisnode Belgium offered &#8220;Data quality&#8221;, (to improve the quality of its customers&#8217; data), and &#8220;Data Delivery&#8221;, (to provide data to its customers, especially for the implementation of marketing campaigns). These databases consisted of personal data and user profiles from various external sources.&nbsp;<\/p>\n\n\n\n<p>The regulator received a complaint based on the so-called \u2018right of access\u2019 with Bisnode, which allows anyone to request access to the data it keeps about them at any time. The investigation found that the company <a href=\"https:\/\/www.autoriteprotectiondonnees.be\/citoyen\/lapd-sanctionne-lentreprise-de-gestion-de-donnees-black-tiger-belgium-pour-manque-de-transparence\">under its legitimate interest indirectly collected and processed personal data on a large scale, for a long period, (15 years),<\/a> without the data subjects being informed individually, clearly and proactively about the processing carried out. The company also lacked records of its processing activities.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Other enforcement decisions<\/h4>\n\n\n\n<p><strong>Student privacy vs teachers\u2019 authority: <\/strong>The Icelandic data protection authority ruled on personal data processing by the University of Iceland. According to the complaint, a teacher had monitored a student through the teaching site in the Canvas learning management system. However, the supervisory authority concluded that there was no electronic monitoring, as the teacher&#8217;s assessment of the complainant&#8217;s activity in the learning management system was not sustained or repeated regularly. It was also considered that the said processing of personal information had been necessary for the university in connection with statutory tasks entrusted to the university by law.&nbsp;<br><\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/student-849828_1280-1024x682.jpg\" alt=\"\" class=\"wp-image-8209 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/student-849828_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/student-849828_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/student-849828_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/student-849828_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>However, the complainant was not sufficiently informed of the teacher&#8217;s ability to examine their use of the Canvas learning management system and make it the basis for grading. The peer assessment of the complainant&#8217;s fellow students in a group project was one of the factors that formed the basis of the grading for the assessment component. The University&#8217;s processing therefore failed to comply with the transparency requirements under privacy legislation.<\/p>\n<\/div><\/div>\n\n\n\n<p><strong>Biometric scanning abuse:<\/strong> In the UK Serco Leisure, Serco Jersey and seven associated community leisure trusts have been issued enforcement notices ordering them to stop using facial recognition technology and fingerprint scanning to monitor employee attendance. The investigation found that Serco and the trusts have been unlawfully processing the biometric data of more than 2,000 employees at 38 leisure facilities. Serco had <a href=\"https:\/\/ico.org.uk\/action-weve-taken\/enforcement\/serco-leisure-operating-limited-and-relevant-associated-trusts\/\">to record employee attendance to pay workers as per its contractual duties but rejected less invasive options available<\/a>, including timesheets or electronic cards. Although Serco had indicated that these choices may be abused, it had shown no proof of real, widespread misuse.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Data security<\/h4>\n\n\n\n<p><strong>Password retention guide: <\/strong>Too often identity theft is caused by the use of <a href=\"https:\/\/www.gpdp.it\/temi\/cybersecurity\/password\/conservazione-delle-password\">computer authentication credentials stored in databases that are not adequately protected<\/a> with cryptographic functions. Stolen data is used to illicitly enter entertainment sites, (35.6%), social media, (21.9%) and e-commerce portals, (21.2%). In other cases, they allow access to forums and websites of paid services, (18.8%), and financial services, (1.3%). As a result, the Italian data protection authority recently developed an <a href=\"https:\/\/www.gpdp.it\/temi\/cybersecurity\/password\/conservazione-delle-password\">FAQ<\/a> and more detailed <a href=\"https:\/\/www.gpdp.it\/garante\/doc.jsp?ID=9962283\">guidelines regarding password storage<\/a>, providing cryptographic functions currently considered the most secure, (in Italian only).&nbsp;<\/p>\n\n\n\n<p><strong>Cybersecurity core 2.0:<\/strong> America\u2019s NIST has meanwhile released version 2.0 of its landmark Cybersecurity Framework. The agency has finalised the framework\u2019s first major update since its creation in 2014. Now it explicitly aims to help all organisations \u2014 not just those in critical infrastructure, its original target audience \u2014 to manage and reduce risks. The framework\u2019s core is now organised around six key functions: <a href=\"https:\/\/www.nist.gov\/cyberframework\">Identify, Protect, Detect, Respond and Recover, along with CSF 2.0\u2019s newly added Govern function<\/a>. The CSF is used widely internationally. <a href=\"https:\/\/www.nist.gov\/cyberframework\/framework-version-10\">Versions 1.1 and 1.0<\/a> have been translated into 13 languages, and the NIST expects that CSF 2.0 also will be translated by volunteers around the world.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Federated Learning<\/h4>\n\n\n\n<p>The UK Responsible Technology Adoption Unit, in cooperation with the NIST, published a <a href=\"https:\/\/rtau.blog.gov.uk\/2024\/02\/27\/data-distribution-in-privacy-preserving-federated-learning\/\">series of analyses about Privacy-Preserving Federated Learning<\/a>. Organisations often struggle to articulate the benefits of the approach, associated with <a href=\"https:\/\/rtau.blog.gov.uk\/2024\/02\/22\/privacy-preserving-federated-learning-understanding-the-costs-and-benefits\/\">machine learning that involves training a model without the centralised collection of training data<\/a>. This can lead to lower infrastructure and network overheads. However, bespoke privacy infrastructure can introduce additional costs. Plus, there are fewer people with the skills and experience required to design and deploy it.&nbsp;<\/p>\n\n\n\n<p>On the other hand, federated learning allows organisations to use and monetise data assets that would not have previously been accessible. In removing the need for access to the full data, <a href=\"https:\/\/rtau.blog.gov.uk\/2024\/02\/22\/privacy-preserving-federated-learning-understanding-the-costs-and-benefits\/\">it protects the value of the data<\/a> for the data owner. Finally, legal consultation is a necessary cost, but in principle PETs can significantly reduce data protection risks, as when used appropriately, differentially private data can be considered anonymised.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This issue highlights how web browsing data, non-anonymised according to America\u2019s FTC, was sold worldwide in the Avast\/Jumpshot case, the EDPB\u2019s new enforcement action on the right of access, cloud outsourcing in the banking sector, the NIST\u2019s new cybersecurity framework for all organisations, and federated learning analysis. Stay tuned! Sign up to receive our fortnightly [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":8222,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[129,179,122,98,35,265,79,103],"class_list":["post-8198","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-consumer-data-protection","tag-data-brokers","tag-data-subject-access-requests","tag-direct-marketing","tag-gdpr","tag-generative-ai","tag-international-transfers","tag-tech-vendor"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>This issue highlights how web browsing data, non-anonymised according to America\u2019s FTC, was sold worldwide in the Avast\/Jumpshot case, the EDPB\u2019s new enforcement action on the right of access, cloud outsourcing in the banking sector, the NIST\u2019s new cybersecurity framework for all organisations, and federated learning analysis. Stay tuned! Sign up to receive our fortnightly digest via email. Web browsing data for sale The UK software provider Avast will have to pay 16.5 million dollars to the US Federal Trade Commission, and the business will not be allowed to sell or license any web browsing data for advertising purposes. Avast&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>This issue highlights how web browsing data, non-anonymised according to America\u2019s FTC, was sold worldwide in the Avast\/Jumpshot case, the EDPB\u2019s new enforcement action on the right of access, cloud outsourcing in the banking sector, the NIST\u2019s new cybersecurity framework for all organisations, and federated learning analysis. Stay tuned! Sign up to receive our fortnightly digest via email. Web browsing data for sale The UK software provider Avast will have to pay 16.5 million dollars to the US Federal Trade Commission, and the business will not be allowed to sell or license any web browsing data for advertising purposes. Avast&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 18 Feb - 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0 - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data privacy stories: web browsing data for sale, US-restricted data transfers and cybersecurity\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 18 Feb - 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0 - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data privacy stories: web browsing data for sale, US-restricted data transfers and cybersecurity\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-05T10:51:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-03T08:36:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 18 Feb &#8211; 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0\",\"datePublished\":\"2024-03-05T10:51:50+00:00\",\"dateModified\":\"2025-02-03T08:36:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/\"},\"wordCount\":2214,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/internet-3116062_1280.jpg\",\"keywords\":[\"consumer data protection\",\"data brokers\",\"data subject access requests\",\"direct marketing\",\"GDPR\",\"generative AI\",\"International transfers\",\"tech vendor\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/\",\"name\":\"Data protection digest 18 Feb - 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0 - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/internet-3116062_1280.jpg\",\"datePublished\":\"2024-03-05T10:51:50+00:00\",\"dateModified\":\"2025-02-03T08:36:02+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data privacy stories: web browsing data for sale, US-restricted data transfers and cybersecurity\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/internet-3116062_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/internet-3116062_1280.jpg\",\"width\":1280,\"height\":853,\"caption\":\"web browsing data\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 18 Feb &#8211; 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 18 Feb - 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0 - TechGDPR","description":"TechGDPR\u2019s review of the most important data privacy stories: web browsing data for sale, US-restricted data transfers and cybersecurity","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 18 Feb - 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0 - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data privacy stories: web browsing data for sale, US-restricted data transfers and cybersecurity","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/","og_site_name":"TechGDPR","article_published_time":"2024-03-05T10:51:50+00:00","article_modified_time":"2025-02-03T08:36:02+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 18 Feb &#8211; 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0","datePublished":"2024-03-05T10:51:50+00:00","dateModified":"2025-02-03T08:36:02+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/"},"wordCount":2214,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg","keywords":["consumer data protection","data brokers","data subject access requests","direct marketing","GDPR","generative AI","International transfers","tech vendor"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/","name":"Data protection digest 18 Feb - 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0 - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg","datePublished":"2024-03-05T10:51:50+00:00","dateModified":"2025-02-03T08:36:02+00:00","description":"TechGDPR\u2019s review of the most important data privacy stories: web browsing data for sale, US-restricted data transfers and cybersecurity","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/internet-3116062_1280.jpg","width":1280,"height":853,"caption":"web browsing data"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05032024-web-browsing-data-for-sale-us-restricted-data-transfers-and-cybersecurity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 18 Feb &#8211; 2 Mar 2024: web browsing data for sale, banking sector outsourcing, cybersecurity core 2.0"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=8198"}],"version-history":[{"count":23,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8198\/revisions"}],"predecessor-version":[{"id":10287,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8198\/revisions\/10287"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/8222"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=8198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=8198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=8198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}