{"id":8877,"date":"2024-08-19T11:53:01","date_gmt":"2024-08-19T09:53:01","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=8877"},"modified":"2024-08-19T12:21:24","modified_gmt":"2024-08-19T10:21:24","slug":"data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/","title":{"rendered":"Data protection digest 3 &#8211; 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks"},"content":{"rendered":"\n<p><em>In this issue: X\u2019s AI Grok training suspended in the EU,\u00a0 third-party cookies may lead to data breaches, Uniqlo \u2018payroll\u2019 mistake, car rental refusal based on client\u2019s income, and AI non-transparency &#8211; data scraping, maximisation, risks of regurgitation, and what is behind data labelling for the LLMs industry.<\/em><\/p>\n\n\n\n<p><em><a href=\"#newslettersignup\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/a><\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">LLMs, data labelling and data protection<\/h4>\n\n\n\n<p>A fundamental principle of data protection law is data minimisation. Privacy International however insists that LLMs are being trained through indiscriminate data scraping and generally maximise their approach to data collection. Under data protection laws, individuals have the right to assert control over data related to them. However, <a href=\"https:\/\/privacyinternational.org\/explainer\/5353\/large-language-models-and-data-protection\">LLMs are unable to adequately uphold these rights<\/a>, as the information is held within the parameters of a model in addition to a more traditional form, such as a database. &#8216;Regurgitation&#8217; can also lead to personal data being spat out by LLMs. Because training data is enmeshed in LLM algorithms, this can be extracted, (or regurgitated), by feeding in the right prompts.&nbsp;<\/p>\n\n\n\n<p>PI also investigated <a href=\"https:\/\/privacyinternational.org\/explainer\/5357\/humans-ai-loop-data-labelers-behind-some-most-powerful-llms-training-datasets\">digital labour platforms that have arisen to supply data labelling for LLM training<\/a>. This includes training an AI model against a labelled dataset and is supplemented by reinforcement learning from human feedback. For example, data labellers mark raw data points, (images, text, sensor data, etc.), with &#8216;labels&#8217; that help the AI model make crucial decisions, such as for an autonomous vehicle to distinguish a pedestrian from a cyclist. It appeared that many such labellers can be completely disconnected from the AI developers, and are often not informed about who or what they are labelling raw datasets for. They are also subject to algorithmic surveillance and unreliable job stability.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Third-party cookies as a cause of data breaches<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:28% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXe3IuIO9XOIhJGE57qM4_3-oeaFuYxSrQGR3zjZicezkE84hgpufg_eWSOi6WcqKTzEaGhZo3SvbG9uh3XWTuzVFlBRi_es5DUF7fKrWCgCT8upir82JaYX8CqoFE1kBNzcvWV-EvXWiF3IY0bJvxuE10aB?key=ai8QVjhyGibfxkiF9sgnWg\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>JDSupra legal insights look at the disclosure of data through website cookies which may facilitate a data breach in California. In the related court case, the plaintiff claimed that an online counselling service where website users can find and seek therapy violated the California Consumer Privacy Act by allowing tracking software to retarget website users with ads. The court refused to dismiss the data breach claim. Specifically, the simple fact a <a href=\"https:\/\/www.jdsupra.com\/legalnews\/disclosure-of-data-through-website-1209433\/\">user visited the website, may qualify as sensitive information because such a visit could mean they must have been seeking therapy<\/a>. <\/p>\n<\/div><\/div>\n\n\n\n<p>Concerning whether using retargeting cookies is inherently illegal, the court refrained from rendering a decision.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">US <strong>Child privacy bill<\/strong><\/h4>\n\n\n\n<p>On 30 July, the Kids Online Safety and Privacy Act was passed by the Senate. KOSPA is a variation of two previously proposed bills: the Kids Online Safety Act, (KOSA), and the amended Child Online Privacy Protection Act, (COPPA 2.0). The act applies to digital platforms, particularly those with more than 10 million active monthly users. The duty of care includes options for minors to protect their data, prohibition of the use of dark patterns, and transparency regarding the use of opaque algorithms, etc. KOSPA now heads to the House, where it will be <a href=\"https:\/\/www.theguardian.com\/us-news\/article\/2024\/aug\/03\/kids-online-safety-act-senate\">debated over potential censorship<\/a> and the possibility of minors lacking access to vital information.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Oncological oblivion<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdwUzVToVj_gzT0wE5VoHwUmRM7IbQQtQbGb7JTwe9-VOmRq1P31BndDOFE6M4htZWJGkcFxptkHjQt31ie_YzmKIZo6u5UmB0jm-urbxNSdKFSuEyhH2KyOGGUdwE6CzQmYWXxW4wCcvK6Yl_1W5mZ8h0r?key=ai8QVjhyGibfxkiF9sgnWg\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Italian data protection authority Garante looks at \u201cthe right to be forgotten\u201d in oncology, and whether banks, insurance companies, credit bodies, and employers can ask for information on the <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/10043752\">oncological pathology of an individua<\/a>l in a remission stage. Also, can a clinically recovered person adopt a child? These and other questions are answered in the <a href=\"https:\/\/www.garanteprivacy.it\/oblio-oncologico\">FAQs<\/a> published by the regulator, (in Italian). The aim is to prevent discrimination and protect the rights of people who have recovered from oncological diseases.<\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Chatbots and customer data<\/h4>\n\n\n\n<p><a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/let-op-gebruik-ai-chatbot-kan-leiden-tot-datalekken\">Employees sharing patient or consumer personal information with an AI chatbot<\/a> have resulted in allegations of data leaks to the Dutch Data Protection Authority, (AP). The majority of chatbot developers store all data entered. Organisations must make clear agreements with their employees about the use of AI chatbots.&nbsp; They could also arrange with the provider of a chatbot that it does not store the entered data.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More official guidance<\/h4>\n\n\n\n<p><strong>Avoiding outages and system failures:<\/strong> The US Federal Trade Commission insists that many common types of software flaws can be preemptively addressed through systematic and known processes that minimise the likelihood of outages. This includes rigorous testing of both code and configuration and the incremental rollout procedures. For instance, when deploying changes to automatically updating software, vendors could <a href=\"https:\/\/www.ftc.gov\/policy\/advocacy-research\/tech-at-ftc\/2024\/08\/avoiding-outages-preventing-widespread-system-failures\">initially deploy it to a small subset of machines, and then roll it out to more users<\/a> after it\u2019s confirmed that the smaller subset has continued to function without interruption.&nbsp;<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"892\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/education-5600987_1280-1024x892.png\" alt=\"data labelling\n\" class=\"wp-image-8888 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/education-5600987_1280-1024x892.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/education-5600987_1280-300x261.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/education-5600987_1280-768x669.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/education-5600987_1280.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Surveys at schools:<\/strong> The Latvian data protection authority investigates if a teacher can ask students to complete surveys. The educational process has long been <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-skolenu-aptaujas\">not limited to the learning of the subject, but the psychological state<\/a> of the child too. Answers given in student surveys can be divided into standard, personalised or anonymous forms. However, children often are not able to assess how much private information to give to others. Thus, security requirements, such as data non-disclosure and storage limitations must be applied in most cases. <\/p>\n<\/div><\/div>\n\n\n\n<p>Additional parent consent should be required if the surveys are related to the organisation of the learning process indirectly.<\/p>\n\n\n\n<p><strong>AI systems transparency:<\/strong> The German Federal Information Security Office, (BSI), published a white paper on the &#8220;Transparency of AI systems&#8221;. It says that the increasing complexity of the AI \u201cblack boxes\u201d systems as well as missing or inadequate information about them makes it <a href=\"https:\/\/www.bsi.bund.de\/DE\/Service-Navi\/Presse\/Alle-Meldungen-News\/Meldungen\/Whitepapier_KI-Systeme_240805.html\">difficult to make a visual assessment<\/a> or to judge the trustworthiness of the outputs. The paper defines the term transparency for various stakeholders from users to developers, and discusses the opportunities and risks of transparent AI systems, both positive, (promoting safety, data protection, avoiding copyright infringements), and negative, (the possible disclosure of attack vectors).&nbsp;<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_591994b6644dd5fe31d0b5143230547b\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Uniqlo \u2018payroll\u2019 mistake<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXemoUvMc0FCiUKh8pcfFHsLwaZTDT1x_Z29fBrCFU3EQ5T3-xpRkj8GoBcmXJpfTBLs1_Cjwr0PUitqGeR5eS4n2wPrCMe_ONnnbnaicAFTZceVOD9xeEoRTSr0V_X7AoC7Or3wuxmpQ-5Xg--shlPjCIA?key=ai8QVjhyGibfxkiF9sgnWg\" alt=\"data labelling\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Spanish regulator imposed a fine of 450,000 euros, (reduced to 270,000 euros), on the UNIQLO branch in Spain, DataGuidance reports. The complainant, who provided services to UNIQLO, requested their payroll data and received an email containing a PDF document with <a href=\"https:\/\/www.aepd.es\/documento\/ps-00238-2024.pdf\">payroll information on the entire 446-strong workforce<\/a>. The document contained names, surnames, social security, bank account numbers, and more. <\/p>\n<\/div><\/div>\n\n\n\n<p>The breach was caused by a human error within the human resources department, but the employee in question had not informed their superior.&nbsp;The regulator confirmed that the <a href=\"https:\/\/www.dataguidance.com\/news\/spain-aepd-fines-uniqlo-europe-ltd-450000-following\">negligent action of the employee does not exempt the data controller from liability<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Healthcare IT provider fine<\/strong><\/h4>\n\n\n\n<p>The UK Information Commissioner\u2019s Office has provisionally decided to fine <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/08\/provisional-decision-to-impose-6m-fine-on-software-provider-following-2022-ransomware-attack\/\">Advanced Computer Software Group<\/a> 6.09 million pounds. It provides IT and <a href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-20062024-software-testing-email-management-affordable-data-security\/\">software services<\/a> to the NHS and other healthcare providers, and handles people\u2019s personal information on behalf of these organisations as their data processor. The decision relates to a ransomware incident in 2022, when hackers accessed several of Advanced\u2019s health and care systems, (with the personal information of 82,946 people), via a <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/08\/provisional-decision-to-impose-6m-fine-on-software-provider-following-2022-ransomware-attack\/\">customer account that did not have multi-factor authentication<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More enforcement decisions<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcMPaneGxyQaJhsTGsDo6mNgGpvAeM1YsrHessnrp-QF2UjFMVlS_MtD77nSDo6GZcAuTsaH2tM3o64NRq6RhpI8tmFliEphYs5hqDIxVJ2NH3HgNm4SYJorWoffh6Nsw9yNkwl7SEI0cazTlozQd-HW1Gt?key=ai8QVjhyGibfxkiF9sgnWg\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Car rental and client\u2019s income: <\/strong>The Italian Garante imposed a one million euro fine on Credit Agricole Auto Bank for the illicit processing of personal and income data of customers who requested financing for the long-term rental of a car. The <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/10043752\">bank accessed the centralised fraud prevention system, also on behalf of its subsidiary<\/a>, a car leasing company, despite it not having the necessary authorisation from the Ministry of Finance.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>The complainant contacted the bank to know the reasons behind the denial of the long-term rental and the inclusion of their name on a credit risk list. The bank stated these were due to the client&#8217;s negative income situation. Furthermore, the bank did not first acquire the client&#8217;s tax return form, an essential document for making a comparison with the information contained in the database.&nbsp;<\/p>\n\n\n\n<p><strong>Dark patterns in the gambling industry:<\/strong> The Guernsey privacy regulator reviewed 19 online gaming sites for indicators of deceptive designs. In 42% of cases, the analysis was unable to find the website or app\u2019s privacy settings, (in most cases those found were unnecessarily lengthy and complex). Also, it was more difficult to delete an account than it was to create one. In one of the instances, a user made their account <a href=\"https:\/\/www.odpa.gg\/news\/news-article\/?id=dccb80cb-3156-ef11-bfe3-000d3a2d37f7\">deletion request through an on-site chatbot,<\/a> as they were unable to find the \u2018delete account\u2019 option on the site. In another case, the organisation asked that a form be completed and returned to them, along with identity verification documents. Neither the documents nor the form were required to create an account.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Data security<\/h4>\n\n\n\n<p><strong>Lack of encryption:<\/strong> The Danish regulator has reprimanded the Vejen Municipality for insufficient security measures. Three <a href=\"https:\/\/www.datatilsynet.dk\/afgoerelser\/afgoerelser\/2024\/aug\/endnu-en-kommune-indstillet-til-boede-for-manglende-kryptering\">stolen computers with information about children<\/a> were not encrypted &#8211; and the same turned out to be the case with up to 300 other computers in the municipality. The computers were only intended for use by teachers as part of the teaching process. In practice, however, they were also used by teachers to make status descriptions of students, class handovers, etc. The regulator also issued a reminder that encryption of portable devices is a <a href=\"https:\/\/www.datatilsynet.dk\/afgoerelser\/afgoerelser\/2024\/aug\/endnu-en-kommune-indstillet-til-boede-for-manglende-kryptering\">very basic security measure which is relatively easy and not very costly to implement<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/car-4073514_1280-1024x682.jpg\" alt=\"\" class=\"wp-image-8878 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/car-4073514_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/car-4073514_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/car-4073514_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/car-4073514_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>GPS tracking:<\/strong> A court in Slovenia confirmed the decision of the Information Commissioner to restrict the use of GPS tracking of company vehicles, on a systematic, automated and continuous basis. The company did not demonstrate that such GPS tracking is a suitable and necessary measure for the protection of company vehicles and the equipment and documentation contained in them, nor to ensure employee safety or for the enforcement of potential legal claims and defence against them.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>Among other things, the court confirmed that the data obtained by the operator through the GPS tracking of company vehicles constitutes employees\u2019 data, even though it is not recorded and stored in the tracking system itself, as the <a href=\"https:\/\/www.ip-rs.si\/novice\/sodba-upravnega-sodi%C5%A1%C4%8Da-v-zvezi-z-izvajanjem-gps-sledenja-slu%C5%BEbenih-vozil-1723021141\">employees as drivers can be identified with the help of other documents, (eg, travel orders)<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">AI Grok<\/h4>\n\n\n\n<p>X agreed with the Irish Data Protection Commission to suspend the processing of the <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/press-releases\/dpc-welcomes-xs-agreement-suspend-its-processing-personal-data-purpose-training-ai-tool-grok\">personal data contained in the public posts of X\u2019s EU\/EEA users<\/a>, (processed between 7 May and 1 August), to train its AI \u2018Grok\u2019. The suspension will last while the DPC examines, together with other regulators, the extent to which the processing complies with the GDPR. The agreement was reached after the regulator submitted the case to the country&#8217;s Supreme Court.<\/p>\n\n\n\n<p>In June, <a href=\"https:\/\/about.fb.com\/news\/2024\/06\/building-ai-technology-for-europeans-in-a-transparent-and-responsible-way\/\">Meta<\/a> also agreed with the DPC that it would delay processing EU\/EEA user data for its AI tools. However, unlike Meta, X didn&#8217;t even notify its users beforehand. To make sure that X&#8217;s AI training is properly handled, the privacy advocacy group <a href=\"https:\/\/noyb.eu\/en\/twitters-ai-plans-hit-9-more-gdpr-complaints\">NOYB<\/a> has now filed complaints with the data protection authorities in nine countries, (questioning what happened to EU data that had already been ingested into the systems, and how X can effectively distinguish between EU and non-EU data).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this issue: X\u2019s AI Grok training suspended in the EU,\u00a0 third-party cookies may lead to data breaches, Uniqlo \u2018payroll\u2019 mistake, car rental refusal based on client\u2019s income, and AI non-transparency &#8211; data scraping, maximisation, risks of regurgitation, and what is behind data labelling for the LLMs industry. Stay up to date! Sign up to [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":8886,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[100,58,235,169,214,231],"class_list":["post-8877","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-cookies","tag-gdpr-compliance","tag-hr","tag-online-user-tracking","tag-sensitive-data","tag-toms"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>In this issue: X\u2019s AI Grok training suspended in the EU,\u00a0 third-party cookies may lead to data breaches, Uniqlo \u2018payroll\u2019 mistake, car rental refusal based on client\u2019s income, and AI non-transparency &#8211; data scraping, maximisation, risks of regurgitation, and what is behind data labelling for the LLMs industry. Stay up to date! Sign up to receive our fortnightly digest via email. LLMs, data labelling and data protection A fundamental principle of data protection law is data minimisation. Privacy International however insists that LLMs are being trained through indiscriminate data scraping and generally maximise their approach to data collection. Under data&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>In this issue: X\u2019s AI Grok training suspended in the EU,\u00a0 third-party cookies may lead to data breaches, Uniqlo \u2018payroll\u2019 mistake, car rental refusal based on client\u2019s income, and AI non-transparency &#8211; data scraping, maximisation, risks of regurgitation, and what is behind data labelling for the LLMs industry. Stay up to date! Sign up to receive our fortnightly digest via email. LLMs, data labelling and data protection A fundamental principle of data protection law is data minimisation. Privacy International however insists that LLMs are being trained through indiscriminate data scraping and generally maximise their approach to data collection. Under data&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 3 - 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: data labelling for LLMs, third-party cookies as a cause of leaks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 3 - 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: data labelling for LLMs, third-party cookies as a cause of leaks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-08-19T09:53:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-19T10:21:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 3 &#8211; 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks\",\"datePublished\":\"2024-08-19T09:53:01+00:00\",\"dateModified\":\"2024-08-19T10:21:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/\"},\"wordCount\":1834,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/big-data-7644543_1280.jpg\",\"keywords\":[\"cookies\",\"GDPR Compliance\",\"HR\",\"online (user) tracking\",\"sensitive data\",\"TOMs\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/\",\"name\":\"Data protection digest 3 - 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/big-data-7644543_1280.jpg\",\"datePublished\":\"2024-08-19T09:53:01+00:00\",\"dateModified\":\"2024-08-19T10:21:24+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: data labelling for LLMs, third-party cookies as a cause of leaks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/big-data-7644543_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/big-data-7644543_1280.jpg\",\"width\":1280,\"height\":853,\"caption\":\"data labelling\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 3 &#8211; 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 3 - 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: data labelling for LLMs, third-party cookies as a cause of leaks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 3 - 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: data labelling for LLMs, third-party cookies as a cause of leaks.","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/","og_site_name":"TechGDPR","article_published_time":"2024-08-19T09:53:01+00:00","article_modified_time":"2024-08-19T10:21:24+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 3 &#8211; 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks","datePublished":"2024-08-19T09:53:01+00:00","dateModified":"2024-08-19T10:21:24+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/"},"wordCount":1834,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg","keywords":["cookies","GDPR Compliance","HR","online (user) tracking","sensitive data","TOMs"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/","name":"Data protection digest 3 - 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg","datePublished":"2024-08-19T09:53:01+00:00","dateModified":"2024-08-19T10:21:24+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: data labelling for LLMs, third-party cookies as a cause of leaks.","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/big-data-7644543_1280.jpg","width":1280,"height":853,"caption":"data labelling"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-19082024-data-labelling-for-llms-third-party-cookies-as-a-cause-of-leaks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 3 &#8211; 16 Aug 2024: data labelling for LLMs, third-party cookies as a cause of leaks"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8877","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=8877"}],"version-history":[{"count":14,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8877\/revisions"}],"predecessor-version":[{"id":8897,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8877\/revisions\/8897"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/8886"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=8877"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=8877"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=8877"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}