{"id":9231,"date":"2024-10-02T11:58:10","date_gmt":"2024-10-02T09:58:10","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=9231"},"modified":"2024-10-02T15:25:05","modified_gmt":"2024-10-02T13:25:05","slug":"data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/","title":{"rendered":"Data protection digest 17 Sep &#8211; 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\"><strong>How does the EU Data Act interact with the GDPR? <\/strong><\/h4>\n\n\n\n<p>The Data Act will become applicable in the EU starting on 12 September 2025. In the runup, the European Commission has published an <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/commission-publishes-frequently-asked-questions-about-data-act\">FAQ<\/a> on the new legislation. Together with the Data Governance Act, it enables a fair distribution of value by establishing clear rules related to the access and use of data within the EU\u2019s data economy. While the Data Act does not regulate the protection of personal data, the GDPR remains fully applicable to all personal data processing activities under the Act.\u00a0<\/p>\n\n\n\n<p>This includes the powers and competences of supervisory authorities and the rights of data subjects. Sometimes, it c<a href=\"https:\/\/www.dlapiper.com\/en\/insights\/publications\/2024\/09\/data-act-frequently-asked-questions-answered-by-the-eu-commission\">omplements the GDPR<\/a>, (eg, real-time portability of data from Internet-of-Things objects). In other cases, it <a href=\"https:\/\/www.eu-data-act.com\/Data_Act_Article_6.html\">restricts the re-use of data<\/a> by third parties, such as for profiling purposes, (unless it is necessary to provide the service to the user). In the event of a conflict between the GDPR and the Data Act, the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/commission-publishes-frequently-asked-questions-about-data-act\">GDPR rules shall prevail<\/a>, (see <a href=\"https:\/\/www.eu-data-act.com\/Data_Act_Article_1.html\">Art. 1(5)<\/a> of the Data Act).\u00a0\u00a0<\/p>\n\n\n\n<p><em><a href=\"#newslettersignup\">Stay up to date! Sign on to receive our fortnightly digest via email<\/a><\/em>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Corrective powers under the GDPR<\/strong><\/h4>\n\n\n\n<p>The CJEU has ruled that a supervisory authority is not obliged to exercise a corrective power in all cases of breach and, in particular, to impose a fine. It may refrain from doing so where the <a href=\"https:\/\/curia.europa.eu\/jcms\/upload\/docs\/application\/pdf\/2024-09\/cp240149en.pdf\">controller has already taken the necessary measures on their initiative<\/a>. The case relates to a savings bank in Germany where one of its employees had consulted a customer&#8217;s data on several occasions without being authorised to do so. The employee had confirmed in writing that she had neither copied nor retained or shared the data, and the bank had taken disciplinary measures. The data controller nevertheless notified the data protection authority of this breach.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcCt_2uTP7EimbfrRhKwf1ryAbb0JyI8mtAnoPA_hyQtNREastlw0JiCIKUYpCad04gHZP6iw6QIOUovAbyU6_LBtL6stVb29glGuaIFAVajmxEBFYre4lzj8KyaZlNZ1q3wj_F1_7h8x4dDyto0HGjxi75?key=XO_iB6nrc4haQpnANwaz3w\" alt=\"Data Act\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>California tech updates:<\/strong> Among over a <a href=\"https:\/\/natlawreview.com\/article\/california-enacts-additional-generative-ai-bills-touching-training-data-and\">dozen new bills<\/a> covering personal data and generative AI, Governor Gavin Newsom signed a bill on <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202320240AB2013\">training data sources<\/a> into law. It includes reporting provisions for developers on sources or owners of datasets, a description of data points in them, whether the datasets contain personal information, how the datasets further the intended purpose of the AI system or service, whether the datasets include any data protected by copyright, trademark, or patent and more. Changes will be due on 1 January 2026.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>California has also expanded the definition of <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202320240AB1008\">personal data to more abstract digital formats<\/a>, including compressed or encrypted files, metadata, or artificial intelligence systems that are capable of outputting personal information. At the same time, a landmark artificial intelligence safety bill was blocked by the governor after strong opposition from major technology companies. The draft bill required the most <a href=\"https:\/\/www.bbc.com\/news\/articles\/cj9jwyr3kgeo\">powerful AI models to undergo safety testing<\/a> and other oversight obligations.<\/p>\n\n\n\n<p><strong>Lax social media privacy controls: <\/strong>The Federal Trade Commission has examined the data practices of major social media and video streaming services, revealing they engaged in vast surveillance of consumers to monetize their personal information while failing to adequately protect users online, especially minors. Among other things, companies feed users\u2019 and non-users personal information into their automated systems, including for use by their <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2024\/09\/ftc-staff-report-finds-large-social-media-video-streaming-companies-have-engaged-vast-surveillance\">algorithms, data analytics, and AI, without proper testing and oversight<\/a>. Meanwhile, data subjects had little or no way to opt out of how their data was used by these automated systems.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Who determines how to secure data? <\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfYlWtTp09rByhlUD0ZkR74EatSn--wyAJIdycUYAPeqbqTjqHBiTRm8SlYY1FV7zqnLXQDnJVjkaRWDxKakzdm-rA-5PVz6Ou7Gl_7KeaJureue2hHmQQXH7LaknZjkLqCQQ9JhanM9QXoEzCyVYkYra5r?key=XO_iB6nrc4haQpnANwaz3w\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Polish Supreme Administrative Court has made a final decision on whether a data controller can use an employee to determine how to secure data. In a related case, the probation officer of a district court lost an unencrypted pendrive with the personal data of 400 people. The analysis of the case showed that the controller had not fulfilled security obligations correctly.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>Before the incident, the controller issued the device and instructed the probation officer to implement security measures on their own.&nbsp;The <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3368\">obligation to register and encrypt the medium was introduced only after the officer lost<\/a> it. Additionally, employees were only given basic training in data protection, which did not give them enough knowledge on securing digital mediums or calculating the risks of data loss. As a result, the <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3368\">employee decided to protect the data by carrying their drive in a locked bag<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<p><strong>Data accountability from A to Z: <\/strong>The Luxembourg data protection and cybersecurity authorities have recently developed <a href=\"https:\/\/daaz-gdpr.lu\/\">DAAZ, a GDPR compliance tool<\/a> that addresses the challenges faced by start-ups and small and medium-sized enterprises, (available in English). The tool comes in response to the personal data protection challenges faced by SMEs in particular, which are often at a disadvantage compared with large organisations in terms of resources and expertise.<\/p>\n\n\n\n<p><strong>Mobile applications: <\/strong>The French CNIL has published the final version of its recommendations to help professionals design privacy-friendly mobile applications. From 2025, these will be the subject of a specific control campaign. According to the latest data, a typical French consumer downloads 30 apps and uses their mobile phone for an average of 3 hours and 30 minutes per day. Among other things, the recommendations include best practices for stakeholders to <a href=\"https:\/\/www.cnil.fr\/fr\/applications-mobiles-la-cnil-publie-ses-recommandations-pour-mieux-proteger-la-vie-privee\">ensure that users understand whether the requested permissions are really necessary for the application to function<\/a>.<\/p>\n\n\n\n<p><strong>AI Act and GDPR: <\/strong>Finally, the Belgian regulator published its information <a href=\"https:\/\/www.gegevensbeschermingsautoriteit.be\/publications\/information-brochure-on-artificial-intelligence-systems-and-the-gdpr.pdf\">guide<\/a>, (available in English), on the EU AI Act from a GDPR perspective. It includes sections on AI system definition, and data protection principles such as purpose limitation, data minimisation and data subject rights in an <a href=\"https:\/\/techgdpr.com\/blog\/intersection-of-ai-and-ethics\/\">AI context<\/a>. It also emphasizes <a href=\"https:\/\/www.gegevensbeschermingsautoriteit.be\/publications\/information-brochure-on-artificial-intelligence-systems-and-the-gdpr.pdf\">accountability, security measures and human oversight<\/a> in AI development.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Termination of employment<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfbLSKRttCoZ9CkG1n0gT1wB5lvVJz_7v16yr2XMUioWggnycip68XdlsHhgmR6-iGwsNAFX2gnQ-GuQ9tbxvUpaAI_aPXDwt7cN4nTAiZitwKodfzcezgT_2RhfcVzPez36AvA-KENwMTtEzNWlMM7MKc?key=XO_iB6nrc4haQpnANwaz3w\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>Although former employees <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-personas-datu-apstrade-pec-darba-tiesisko-attiecibu-izbeigsanas\">have the right to request the deletion of their data, it should be understood that this right is not absolute<\/a>, according to the Latvian regulator. In one example, the former employer has the right to temporarily retain an e-mail box for a certain period to ensure continuous communication with the company&#8217;s customers, (eg, by forwarding e-mails), and access information that is essential to the operation of the company. However, the employer must clearly define for how long this e-mail address will be stored and communicate it to employees.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p><strong> <\/strong>This does not mean that the employer can use the information found in the e-mail for other purposes. The principle of purpose limitation should be taken into account here. If an employer recovers, for example, a computer or smartphone used by an employee after the end of the employment relationship, they may discover that private e-mails or other communication channels were accessed on it. <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-personas-datu-apstrade-pec-darba-tiesisko-attiecibu-izbeigsanas\">If the employee is not logged out of these accounts, the employer has no right of access, despite owning the device<\/a>.<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_016a60e632cbde3f50f9f9b07a26d0bc\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Data requests via a representative<\/strong><\/h4>\n\n\n\n<p> Finland\u2019s data protection commissioner has stated that a person can make an inspection request for their data with the help of an agent and, for example, ask the organisation to provide the agent with that information. Data protection legislation <a href=\"https:\/\/tietosuoja.fi\/-\/apulaistietosuojavaltuutettu-omien-tietojen-tarkastuspyynnossa-voi-kayttaa-asiamiesta\">does not prevent the exercise of data protection rights through another person<\/a>. An individual who contacted the regulator&#8217;s office had asked the Tax Administration to deliver all information about them to their representative&#8217;s postal address. However, the Tax Administration refused to provide information to the agent, citing that the information could only be provided to the person directly.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More enforcement decisions<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcq4H1yk5O66JBxV_TReJBZ3VDEd3nRcAL5vHeWyep4W-wsgntqnBcfX9v1ssUkTxndKth1oqN_lgYVtfkK5m2h5lQt2Z98J0B2CdMBmGrky1NIHK4_-1cK-T3Qm3Y73w0JRJVptqJ7uCPtGV0G_h9n74M?key=XO_iB6nrc4haQpnANwaz3w\" alt=\"Data Act\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Commercial legitimate interest:<\/strong> Hogan Lovells&#8217; law blog reports that a Dutch court once again has recalled a decision of the data protection authority for its overly<a href=\"https:\/\/www.engage.hoganlovells.com\/knowledgeservices\/news\/dutch-dpas-fine-decision-suspended-by-dutch-court-amidst-commercial-legitimate-interest-controversy_1\"> strict interpretation that purely commercial interests cannot be legitimate interests under the GDPR<\/a>. The court ruled in favour of the unnamed company by suspending a 120,000 euro fine, as there was still room for legal discussion.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>The cumulative criteria for a valid legitimate interest, (eg, for direct commercial marketing), requires a careful assessment, including whether the data subject could reasonably expect the data processing. Additionally, the personal data concerned should be strictly necessary for the legitimate interests pursued, and, finally, the fundamental rights and freedoms of the data subject must be preserved.&nbsp;<\/p>\n\n\n\n<p><strong>Meta fine for password storage in plaintext: <\/strong>The Irish Data Protection Commission has fined Meta Ireland 91 million euros. This inquiry was launched in April 2019, after the company notified the regulator that it had inadvertently stored certain passwords of social media users in \u2018plaintext\u2019 on its internal systems, (eg, <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/press-releases\/DPC-announces-91-million-fine-of-Meta\">without cryptographic protection or encryption<\/a>). These passwords were not made available to external parties.&nbsp;<\/p>\n\n\n\n<p><strong>Selling data to competitors: <\/strong>A man in the UK has pleaded guilty and been fined for unlawfully retaining and selling thousands of details of customer records from the car leasing company he worked for. Shortly before he resigned from his role as sales consultant, at Leaseline Vehicle Management Ltd, he <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/09\/guilty-car-salesman-fined-for-retaining-and-selling-data-to-competitors\/\">sold over 3,600 pieces of personal information he\u2019d taken from the company&#8217;s internal customer database<\/a>. He approached multiple competitor companies with this information, whilst claiming that the data belonged to him.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Data security<\/h4>\n\n\n\n<p><strong>Facial recognition:<\/strong> The German Data Protection Conference observes that some authorities are already using biometric facial recognition in public spaces, citing non-specific criminal procedural rules. However, the legal framework and the <a href=\"https:\/\/privacyinternational.org\/long-read\/5407\/your-new-guide-surveillance-human-rights-standards-here\">civil liberties of those affected &#8211; potentially all citizens<\/a> &#8211; are not sufficiently taken into account. For this reason, the European legislators have excluded certain applications in the AI Act and set strict limits for others. The regulator calls upon the national legislators to <a href=\"https:\/\/datenschutzkonferenz-online.de\/media\/en\/2024-09-20_Entschliessung_DSK_Gesichtserkennung.pdf\">create specific and proportionate legal bases for the use of facial recognition systems<\/a> in public spaces.&nbsp;&nbsp;<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfwoZYqjQ3kw2dQwJrO_uWfaZlUhfa-9QmgcX_Wg4MD6WDd5ZQ-xKnG4wYvV8pPc5BDm7SqbodQfM6LzneVjbZsx66DzNdzY9Mv-ic36-5atSFvLkbnBItynaOkD3KIz1ReDb8SDIN0m9s3hAzZQjLxVqRR?key=XO_iB6nrc4haQpnANwaz3w\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Minor&#8217;s data: <\/strong>Following the UK Ofcom\u2019s publication of the draft Children&#8217;s <a href=\"https:\/\/www.ofcom.org.uk\/online-safety\/illegal-and-harmful-content\/quick-guide-to-childrens-safety-codes\/\">Codes of Practice<\/a> which are due to come into effect in early 2025, <a href=\"https:\/\/connectedworld.clydeco.com\/post\/102jk5r\/online-safety-instagram-improves-privacy-and-parental-control-for-teenagers\">Instagram has changed the way it works for minors<\/a>, connectedworld.clydeco.com reports. For all under 18s, the new &#8220;teen accounts&#8221; will activate several privacy settings by default, such as <a href=\"https:\/\/about.instagram.com\/blog\/announcements\/instagram-teen-accounts\">preventing non-followers from seeing their material and requiring them to manually accept<\/a> new followers. <\/p>\n<\/div><\/div>\n\n\n\n<p>Also, the only way for 13 to 15-year-olds to change the settings is to add a parent or guardian to their account. Strict guidelines will also be applied to sensitive content to avoid suggesting potentially dangerous material and muting notifications overnight, (\u201csleep mode\u201d).&nbsp;<\/p>\n\n\n\n<p><strong>Portability right:<\/strong> A new portability right applies to employees and consumers in Qu\u00e9bec, JD Supra law blog reports. The purpose is to <a href=\"https:\/\/www.jdsupra.com\/legalnews\/new-portability-right-applies-to-4792936\/\">allow individuals in private and public sectors to access their data and transfer<\/a> it to another legally authorised organization of their choice. It only applies to <a href=\"https:\/\/www.quebec.ca\/gouvernement\/travailler-gouvernement\/travailler-fonction-publique\/services-employes-etat\/conformite\/protection-des-renseignements-personnels\/acces-aux-renseignements-personnels\/droit-portabilite\">data that has already been digitally stored<\/a>,&nbsp;and directly provided by the individual. Though the legislation does not specify any particular format. PDFs, pictures, and proprietary formats that call for additional software or costly licensing should be avoided in favour of formats like CSV, XML, or JSON.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How does the EU Data Act interact with the GDPR? The Data Act will become applicable in the EU starting on 12 September 2025. In the runup, the European Commission has published an FAQ on the new legislation. Together with the Data Governance Act, it enables a fair distribution of value by establishing clear rules [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":9234,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94,88],"tags":[51,173,122,98,165,35,231],"class_list":["post-9231","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","category-gdpr","tag-artificial-intelligence","tag-data-act","tag-data-subject-access-requests","tag-direct-marketing","tag-employment-data","tag-gdpr","tag-toms"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png",1280,915,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-300x214.png",300,214,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-768x549.png",640,458,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-1024x732.png",640,458,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png",1280,915,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png",1280,915,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-200x200.png",200,200,true]},"post_excerpt_stackable":"<p>How does the EU Data Act interact with the GDPR? The Data Act will become applicable in the EU starting on 12 September 2025. In the runup, the European Commission has published an FAQ on the new legislation. Together with the Data Governance Act, it enables a fair distribution of value by establishing clear rules related to the access and use of data within the EU\u2019s data economy. While the Data Act does not regulate the protection of personal data, the GDPR remains fully applicable to all personal data processing activities under the Act.\u00a0 This includes the powers and competences&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png",1280,915,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-300x214.png",300,214,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-768x549.png",640,458,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-1024x732.png",640,458,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png",1280,915,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png",1280,915,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280-200x200.png",200,200,true]},"post_excerpt_stackable_v2":"<p>How does the EU Data Act interact with the GDPR? The Data Act will become applicable in the EU starting on 12 September 2025. In the runup, the European Commission has published an FAQ on the new legislation. Together with the Data Governance Act, it enables a fair distribution of value by establishing clear rules related to the access and use of data within the EU\u2019s data economy. While the Data Act does not regulate the protection of personal data, the GDPR remains fully applicable to all personal data processing activities under the Act.\u00a0 This includes the powers and competences&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 17 Sep - 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 17 Sep - 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-10-02T09:58:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-10-02T13:25:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"915\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 17 Sep &#8211; 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle\",\"datePublished\":\"2024-10-02T09:58:10+00:00\",\"dateModified\":\"2024-10-02T13:25:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/\"},\"wordCount\":1799,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/chess-8691908_1280.png\",\"keywords\":[\"Artificial Intelligence\",\"Data Act\",\"data subject access requests\",\"direct marketing\",\"employment data\",\"GDPR\",\"TOMs\"],\"articleSection\":[\"Data Protection Digest\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/\",\"name\":\"Data protection digest 17 Sep - 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/chess-8691908_1280.png\",\"datePublished\":\"2024-10-02T09:58:10+00:00\",\"dateModified\":\"2024-10-02T13:25:05+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/chess-8691908_1280.png\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/chess-8691908_1280.png\",\"width\":1280,\"height\":915,\"caption\":\"Data Act\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 17 Sep &#8211; 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 17 Sep - 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 17 Sep - 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/","og_site_name":"TechGDPR","article_published_time":"2024-10-02T09:58:10+00:00","article_modified_time":"2024-10-02T13:25:05+00:00","og_image":[{"width":1280,"height":915,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png","type":"image\/png"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 17 Sep &#8211; 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle","datePublished":"2024-10-02T09:58:10+00:00","dateModified":"2024-10-02T13:25:05+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/"},"wordCount":1799,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png","keywords":["Artificial Intelligence","Data Act","data subject access requests","direct marketing","employment data","GDPR","TOMs"],"articleSection":["Data Protection Digest","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/","name":"Data protection digest 17 Sep - 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png","datePublished":"2024-10-02T09:58:10+00:00","dateModified":"2024-10-02T13:25:05+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/10\/chess-8691908_1280.png","width":1280,"height":915,"caption":"Data Act"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02102024-eu-data-act-as-an-illustration-of-the-gdpr-prevail-principle\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 17 Sep &#8211; 1 Oct 2024: EU Data Act as an illustration of the GDPR \u2018prevail\u2019 principle"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=9231"}],"version-history":[{"count":10,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9231\/revisions"}],"predecessor-version":[{"id":9244,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9231\/revisions\/9244"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/9234"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=9231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=9231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=9231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}