{"id":9197,"date":"2024-09-18T11:35:20","date_gmt":"2024-09-18T09:35:20","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=9197"},"modified":"2024-09-18T13:45:05","modified_gmt":"2024-09-18T11:45:05","slug":"data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/","title":{"rendered":"Data protection digest 2 &#8211; 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR"},"content":{"rendered":"\n<p><em>In this digest we look at the perception of the term privacy in the digital era, data protection measures when concluding \u201casset deals\u201d, the new SCCs initiative for international transfers from the EU, the probability method and data accuracy, and much more.<\/em><\/p>\n\n\n\n<p><em><a href=\"#newslettersignup\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/a><\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>New SCCs initiative<\/strong><\/h4>\n\n\n\n<p> The European Commission started work on new SCCs for data transfer to third-country data importers, (controllers and processors), <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/14404-Standard-contractual-clauses-for-the-transfer-of-data-to-third-country-controllers-and-processors-subject-to-the-GDPR_en\">subject to the GDPR<\/a>. They will complement the existing clauses for data transfers to third-country importers not subject to the GDPR. Adopted in 2021, the latest set of SCC does not work for importers whose processing operations are subject to the GDPR under Art. 3, as they would duplicate and, in part,<a href=\"https:\/\/commission.europa.eu\/law\/law-topic\/data-protection\/international-dimension-data-protection\/new-standard-contractual-clauses-questions-and-answers-overview_en\"> deviate from the obligations that already follow directly from the GDPR<\/a>.&nbsp; Despite the Commission&#8217;s call for action three years ago, SCCs for those specific cases were not introduced, leaving organisations in legal uncertainty, (see Uber&#8217;s <a href=\"https:\/\/www.euractiv.com\/section\/data-privacy\/news\/dutch-data-protection-authority-hits-uber-with-e290-million-fine-for-violating-eu-data-protection-rules\/\">latest fine<\/a>).&nbsp;<\/p>\n\n\n\n<p>The adoption of the new SCCs is planned for the second quarter of 2025.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Australia privacy reinforcement<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:26% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/map-8526430_1280-1024x768.jpg\" alt=\"New SCCs\" class=\"wp-image-9201 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/map-8526430_1280-1024x768.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/map-8526430_1280-300x225.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/map-8526430_1280-768x576.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/map-8526430_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The parliament introduced and held its first reading on the <a href=\"https:\/\/www.aph.gov.au\/Parliamentary_Business\/Bills_Legislation\/Bills_Search_Results\/Result?bId=r7249\">amendments to the privacy legislation<\/a> to introduce a range of measures, including expanding the Information Commissioner\u2019s powers, facilitating information sharing in emergencies or following eligible data breaches, requiring the development of a Children\u2019s Online Privacy Code, providing protections for overseas data transfers, introducing new civil penalties and <a href=\"https:\/\/ministers.ag.gov.au\/media-centre\/speeches\/second-reading-speech-privacy-and-other-legislation-amendment-bill-2024-12-09-2024\">criminal offences, (for a practice known as \u2018doxxing\u2019)<\/a>, and increasing transparency about automated decisions.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Data disclosure on a party to the contract<\/strong><\/h4>\n\n\n\n<p><strong> <\/strong>The CJEU meanwhile explains the lawfulness of personal data processing in the performance of a contract,&nbsp; <a href=\"https:\/\/www.dataguidance.com\/news\/eu-cjeu-publishes-judgment-lawfulness-processing\">to which the data subject is a party<\/a>. The case relates to a request of a partner seeking to obtain the contact details of other partners, (parties to the contract), with indirect shareholdings in an investment fund through a trust company.&nbsp;<\/p>\n\n\n\n<p>The CJEU ruled that disclosure would be justified only if the main <a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?mode=req&amp;pageIndex=1&amp;docid=290003&amp;part=1&amp;doclang=EN&amp;text=&amp;dir=&amp;occ=first&amp;cid=2040209\">subject matter of the contract could not be achieved if that processing were not to occur<\/a>. If such processing is also necessary for legitimate interests pursued by a controller or third party, it should be strictly necessary to achieve that purpose. While there is a legal obligation for a data controller, it should be foreseeable for those persons subject to disclosure, that the disclosure is proportionate, and meets an objective of public interest.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Dark patterns advisory<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/notification-9018074_1280-1024x682.jpg\" alt=\"New SCCs\" class=\"wp-image-9206 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/notification-9018074_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/notification-9018074_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/notification-9018074_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/notification-9018074_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The California Privacy Protection Agency issued an enforcement advisory on user interfaces that subvert or impair a consumer\u2019s autonomy, leading to a privacy-averse practice. Businesses should adopt clear and <a href=\"https:\/\/cppa.ca.gov\/pdf\/enfadvisory202402.pdf\">understandable language and offer consumers symmetrical choices<\/a> to avoid impairing and interfering with consumers\u2019 ability to make their choices.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">More official guidance<\/h4>\n\n\n\n<p><strong>Asset deals and data protection: <\/strong>The sale of a company can generally be carried out in two ways, either by transferring shares or by transferring assets and\/or economic goods, explains the German Data Protection Conference. While the data processing in the context of a &#8220;<a href=\"https:\/\/www.datenschutzkonferenz-online.de\/media\/dskb\/2024-09-11_Beschluss%20DSK_%20Asset_Deals.pdf\">share deal&#8221; is possible without any problems, apart from audit procedures,<\/a> since only the shares in a company are transferred, the company otherwise continues unchanged as a data controller; the transmission of personal data in the context of an <a href=\"https:\/\/www.datenschutzkonferenz-online.de\/media\/dskb\/2024-09-11_Beschluss%20DSK_%20Asset_Deals.pdf\">&#8220;asset deal&#8221; requires a differentiated approach in terms of data protection law<\/a>. Read the methodology of the latter case in the original paper (in German).<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:26% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/phone-1074238_1280-1024x682.jpg\" alt=\"\" class=\"wp-image-9204 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/phone-1074238_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/phone-1074238_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/phone-1074238_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/phone-1074238_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>How do you identify a person by phone? <\/strong>The common way is by asking to provide several personal details, such as their first name,&nbsp; email address, username, etc. In this case, the more data is requested, the more likely it is to identify the person accurately, and at the same time, the greater the intrusion into the person&#8217;s privacy. Therefore, the organisation must observe proportionality in its activities. <\/p>\n<\/div><\/div>\n\n\n\n<p>A better practice would be using a key: a <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-kas-janem-vera-identificejot-personu-telefoniski\">password previously agreed upon by both parties chosen by the customer<\/a>, or more sophisticated tools such as a secure electronic signature generator, explains the Latvian regulator.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>Data subject notification upon a breach: <\/strong>People who are victims of a data breach often receive insufficient information from a data controller on what exactly happened, when and what information was leaked, and what they can do themselves to reduce the risks, states the Dutch regulator. Also, warning emails, even if sent within a legal time frame, sometimes lack an alarming title or introduction, with the risk that the recipient may simply not read the message. You can examine some recommendations, and <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/themas\/beveiliging\/datalekken\/zo-informeert-u-slachtoffers-over-een-datalek\">sample notification texts, (in Dutch), here<\/a>.&nbsp;<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_0d1ec6f9da3bd6986ce210c522fa1d6c\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Bank data<\/strong> <\/h4>\n\n\n\n<p>The Polish UODO imposed a fine of approx. 1 million euros on mBank for failure to notify persons affected by a data leak. An employee of a company processing personal data on behalf of mBank made a mistake and sent customer documents to another financial institution. The <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3343\">documents were returned to the bank, but they had already been opened.<\/a> The documents included: all sorts of personal information, identification documents, and information on credit and real estate.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3343\">bank did not notify its customers about the problem<\/a>, even though after reporting the breach the regulator informed them about the need to take such action. The explanations offered by mBank included the fact that the documents were mistakenly sent to an institution that is also bound by banking secrecy, an entity that the bank cooperates with and which, according to the bank, has the status of a trusted entity. The employees of this institution confirmed that they do not have copies of the documents received in error.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Microsoft Teams <\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:26% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"678\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/stack-of-letters-447578_1280-1024x678.jpg\" alt=\"\" class=\"wp-image-9208 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/stack-of-letters-447578_1280-1024x678.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/stack-of-letters-447578_1280-300x199.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/stack-of-letters-447578_1280-768x509.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/stack-of-letters-447578_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Norwegian Data Protection Authority has issued a fine to the University of Agder, (UiA). The university had not implemented suitable measures to safeguard personal data security in its use of Microsoft Teams. In February 2024, an employee at UiA discovered that documents with <a href=\"https:\/\/www.datatilsynet.no\/aktuelt\/aktuelle-nyheter-2024\/overtredelsesgebyr-til-universitetet-i-agder\/\">personal data had been stored in open Teams folders, to which employees had access without an official <\/a>imperative.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>The discrepancy has been ongoing since the university adopted Microsoft Teams in August 2018. Around 16,000 registered users were affected. The information includes, among other things, name, social security number, information about exams, the number of exam attempts and special arrangements. In addition, the discrepancy included an overview of refugees associated with the university.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More enforcement actions<\/h4>\n\n\n\n<p><strong>Health data:<\/strong> Meanwhile the French CNIL fined CEGEDIM SANT\u00c9 800,000 euros for processing health data without authorisation. The company publishes and sells management software to community doctors and health centres. Around 25,000 medical practices and 500 health centres use this software. They allow doctors to manage their agenda, patient records and prescriptions. As part of its activity, the company offers a panel of doctors using one of these software programs <a href=\"https:\/\/www.cnil.fr\/fr\/donnees-de-sante-sanction-de-800-000-euros-societe-cegedim-sante\">to conduct studies. This data was not anonymous, but only pseudonymous<\/a>, so the re-identification of the persons concerned was technically possible.<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:26% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"668\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/cctv-5318438_1280-1024x668.jpg\" alt=\"\" class=\"wp-image-9198 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/cctv-5318438_1280-1024x668.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/cctv-5318438_1280-300x196.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/cctv-5318438_1280-768x501.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/cctv-5318438_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Live cameras in psychiatric hospitals:<\/strong> America&#8217;s FTC reports that surveillance camera company Verkada Inc. failed to provide reasonable security for the personal information it collected, including 150,000 live camera feeds in sensitive areas like psychiatric hospitals, women\u2019s health clinics, elementary schools, and prison cells. These failures allowed a threat actor, in March 2021, to <a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/08\/ftc-says-surveillance-camera-company-verkada-has-lotta-explaining-do-after-lax-data-security\">remotely access Verkada\u2019s customer camera feeds and watch them live<\/a>, without anyone\u2019s knowledge or consent. <\/p>\n<\/div><\/div>\n\n\n\n<p>Despite the invasive security breach, Verkada remained unaware of the threat actor\u2019s intrusive exploration until the threat actor self-reported the hack to the media.<\/p>\n\n\n\n<p><strong>Invalid cookie banners: <\/strong>Finally the Belgian regulator took action against Mediahuis for several infringements in the use of cookie banners on 4 news sites, (De Standaard, Het Belang van Limburg, Het Nieuwsblad, Gazet van Antwerpen). They <a href=\"https:\/\/noyb.eu\/en\/noyb-win-belgian-dpa-settlement-turned-proper-legal-orders-deceptive-cookie-banners\">do not provide a \u201crefuse all\u201d button<\/a> on the first information level of the cookie banner and misleading button colours are used. The complaints were filed by the Austrian non-profit privacy rights organization NOYB, which acted as a mandated representative in the case.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Probabilistic method and GDPR<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:26% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfOJz4CSoSdtxlasc-M2SwcOFW05xwIfETBd7GNwIMipFtytAM7L2HjKJd5Vv6XbYbci0qekYKdjj7YGkmpHYu8ZX6aqZxUetrQ97TX1byXkudBH5LKrO5vpLaUuD0AkShVQKdxGFuXRqYsYqCiiwp6hUlR?key=kqzcsrlPuc8XOfOM7Fg3ig\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong> <\/strong><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>The ability of machine learning and artificial intelligence to handle uncertainty and make predictions in the field of statistics has led to their widespread adoption. However, the <a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/blog\/metodos-probabilisticos-y-cumplimiento-rgpd\">limitations that probabilistic methods present in terms of performance<\/a>, (false negatives, false positives, prediction errors, etc.), can affect the <a href=\"https:\/\/techgdpr.com\/blog\/intersection-of-ai-and-ethics\/\">accuracy and suitability<\/a> of data processing, states the latest Spanish AEPD blogpost.<\/p>\n<\/div><\/div>\n\n\n\n<p>In one example, an estimation operation for age verification with an error of 0.01% in a sample of 1000 adults might be acceptable for some purposes. However, in a sample of all types of users in the EU, (450 million inhabitants), an error of 0.01% means making errors with 45,000 people. A significant number of them would be under 18 years of age and this will probably in some cases generate erroneous estimates classifying them as adults.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Finally, the results obtained with different samples may show how accuracy and effectiveness are strongly influenced by the algorithm, gender, image quality, region of birth, age and the interactions between all these factors.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Big Data<\/h4>\n\n\n\n<p><strong>Privacy \u2018paradox\u2019: <\/strong>The Guernsey data protection authority discusses in a blog that while <a href=\"https:\/\/www.odpa.gg\/news\/news-article\/?id=aec46c4e-cb66-ef11-bfe2-000d3a387c30\">people say they care about privacy, their actions suggest otherwise as they are quick to surrender their personal information<\/a> online. However, there is no paradox in such behaviour. Privacy is not just synonymous with \u201csecrecy\u201d. It can be also about control and autonomy over one\u2019s personal information. In just one example, a person can value privacy and still click \u201cyes\u201d to share their location with a food delivery app.&nbsp;<\/p>\n\n\n\n<p>Positively, more companies now embrace the challenge of the realisation that respecting their customers\u2019 privacy is the best way to earn trust. This is why individuals may now be seeing more prompts for permission to access their cameras or address books, offering the choice to say \u201cyes\u201d or \u201cno\u201d.&nbsp;<\/p>\n\n\n\n<p><strong>AI training:<\/strong> Meta and Google AI training programs are being investigated by the European data protection authorities. The Irish lead regulator DPC commenced a cross-border inquiry into Google\u2019s new foundational AI model Pathways Language Model 2. In question its compliance with the requirement of the <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/press-releases\/data-protection-commission-launches-inquiry-google-ai-model\">Data Protection Impact Assessment,<\/a> before engaging in the processing of the personal data of EU\/EEA data subjects. Meanwhile, <a href=\"https:\/\/www.euronews.com\/next\/2024\/06\/26\/meta-respects-regulator-decision-to-pause-ai-tool-in-eu-as-it-eyes-growth\">Meta<\/a> and <a href=\"https:\/\/www.euractiv.com\/section\/data-privacy\/news\/unresolved-questions-over-xs-deal-with-ireland-to-halt-ai-data-processing\/\">X\u2019s<\/a> AI training programs are still on hold in the EU.\u00a0In parallel, the UK Information Commissioner is monitoring the situation with Meta as it is about to resume, in a couple of weeks, the use of UK <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/09\/ico-statement-in-response-to-metas-announcement-on-user-data-to-train-ai\/\">Facebook and Instagram user data to train generative AI<\/a>. The company took into account the reprimand from the regulator and has made it simpler for users to object to the processing.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this digest we look at the perception of the term privacy in the digital era, data protection measures when concluding \u201casset deals\u201d, the new SCCs initiative for international transfers from the EU, the probability method and data accuracy, and much more. Stay up to date! Sign up to receive our fortnightly digest via email. [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":9213,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94,88],"tags":[129,100,192,106,58,79],"class_list":["post-9197","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","category-gdpr","tag-consumer-data-protection","tag-cookies","tag-dark-patterns","tag-data-breach-notification","tag-gdpr-compliance","tag-international-transfers"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg",1280,878,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-300x206.jpg",300,206,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-768x527.jpg",640,439,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-1024x702.jpg",640,439,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg",1280,878,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg",1280,878,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>In this digest we look at the perception of the term privacy in the digital era, data protection measures when concluding \u201casset deals\u201d, the new SCCs initiative for international transfers from the EU, the probability method and data accuracy, and much more. Stay up to date! Sign up to receive our fortnightly digest via email. New SCCs initiative The European Commission started work on new SCCs for data transfer to third-country data importers, (controllers and processors), subject to the GDPR. They will complement the existing clauses for data transfers to third-country importers not subject to the GDPR. Adopted in 2021,&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg",1280,878,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-300x206.jpg",300,206,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-768x527.jpg",640,439,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-1024x702.jpg",640,439,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg",1280,878,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg",1280,878,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>In this digest we look at the perception of the term privacy in the digital era, data protection measures when concluding \u201casset deals\u201d, the new SCCs initiative for international transfers from the EU, the probability method and data accuracy, and much more. Stay up to date! Sign up to receive our fortnightly digest via email. New SCCs initiative The European Commission started work on new SCCs for data transfer to third-country data importers, (controllers and processors), subject to the GDPR. They will complement the existing clauses for data transfers to third-country importers not subject to the GDPR. Adopted in 2021,&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 2 - 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: New SCCs initiative, data asset deals, probabilistic method and GDPR\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 2 - 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: New SCCs initiative, data asset deals, probabilistic method and GDPR\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-09-18T09:35:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-18T11:45:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"878\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 2 &#8211; 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR\",\"datePublished\":\"2024-09-18T09:35:20+00:00\",\"dateModified\":\"2024-09-18T11:45:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/\"},\"wordCount\":1779,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/IMG_6720.jpg\",\"keywords\":[\"consumer data protection\",\"cookies\",\"dark patterns\",\"data breach notification\",\"GDPR Compliance\",\"International transfers\"],\"articleSection\":[\"Data Protection Digest\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/\",\"name\":\"Data protection digest 2 - 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/IMG_6720.jpg\",\"datePublished\":\"2024-09-18T09:35:20+00:00\",\"dateModified\":\"2024-09-18T11:45:05+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: New SCCs initiative, data asset deals, probabilistic method and GDPR\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/IMG_6720.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/IMG_6720.jpg\",\"width\":1280,\"height\":878,\"caption\":\"New SCCs\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 2 &#8211; 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 2 - 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: New SCCs initiative, data asset deals, probabilistic method and GDPR","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 2 - 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: New SCCs initiative, data asset deals, probabilistic method and GDPR","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/","og_site_name":"TechGDPR","article_published_time":"2024-09-18T09:35:20+00:00","article_modified_time":"2024-09-18T11:45:05+00:00","og_image":[{"width":1280,"height":878,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 2 &#8211; 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR","datePublished":"2024-09-18T09:35:20+00:00","dateModified":"2024-09-18T11:45:05+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/"},"wordCount":1779,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg","keywords":["consumer data protection","cookies","dark patterns","data breach notification","GDPR Compliance","International transfers"],"articleSection":["Data Protection Digest","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/","name":"Data protection digest 2 - 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg","datePublished":"2024-09-18T09:35:20+00:00","dateModified":"2024-09-18T11:45:05+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: New SCCs initiative, data asset deals, probabilistic method and GDPR","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/09\/IMG_6720.jpg","width":1280,"height":878,"caption":"New SCCs"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18092024-new-sccs-initiative-data-asset-deals-probabilistic-method-and-gdpr\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 2 &#8211; 16 Sep 2024: New SCCs initiative, data asset deals, probabilistic method and GDPR"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=9197"}],"version-history":[{"count":10,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9197\/revisions"}],"predecessor-version":[{"id":9219,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9197\/revisions\/9219"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/9213"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=9197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=9197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=9197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}