{"id":9918,"date":"2024-12-18T10:37:58","date_gmt":"2024-12-18T09:37:58","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=9918"},"modified":"2024-12-18T14:20:13","modified_gmt":"2024-12-18T13:20:13","slug":"data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/","title":{"rendered":"Data protection digest 1 &#8211; 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment"},"content":{"rendered":"\n<p><em>In this issue, we explore the <strong>DORA application<\/strong> deadline and its interference with the GDPR; how to conduct an <strong>AI impact assessment <\/strong>or integrate it into your existing privacy risk management processes; what constitutes <strong>US-restricted data transfe<\/strong>r to countries of concern; and what expectations customers have about their data; a <strong>Real-Time Bidding <\/strong>explainer;<strong> a Sky Italia<\/strong> telemarketing fine; and a new <strong>Meta<\/strong> privacy violation<strong>.<\/strong><\/em><\/p>\n\n\n\n<p><em><a href=\"#newslettersignup\">Stay up to date! Sign on to receive our fortnightly digest via email.<\/a><\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>DORA application<\/strong> deadline<\/h4>\n\n\n\n<p><strong> <\/strong>As the Digital Operational Resilience Act will apply from 17 January 2025, the European supervisors have called on <a href=\"https:\/\/www.esma.europa.eu\/sites\/default\/files\/2024-12\/JC_2024_99_ESAs_Statement_on_DORA_application.pdf\">financial entities and third-party providers<\/a> to advance their preparations on the information and communication technology <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32024R2956\">requirements<\/a>. There are also important interfaces between DORA and the GDPR, in data protection experts&#8217; opinion. <a href=\"https:\/\/www.efdpo.eu\/synergies-between-dora-and-gdpr-a-comprehensive-approach-to-data-security\/\">Both regulations aim at ensuring data integrity, confidentiality and availability<\/a>, such as notification of security incidents, risk management, technical and organisational measures, controls and audits. Furthermore, an integrated strategy that considers both data protection and IT security is needed to comply with both regulations.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Third-country authorities<\/strong> and GDPR certification<\/h4>\n\n\n\n<p>The EDPB published guidelines on <a href=\"https:\/\/www.edpb.europa.eu\/news\/news\/2024\/edpb-clarifies-rules-data-sharing-third-country-authorities-and-approves-eu-data_en\">GDPR Art.48<\/a> about data transfers to third-country authorities. The sharing of data with the public authorities in other countries can help collect evidence in the case of a crime, check financial transactions, or approve new medications. The board clarifies how organisations, private and public, can best assess under which conditions they can lawfully respond to such requests.&nbsp;The Board also adopted an opinion approving the Brand Compliance certification criteria concerning processing activities by controllers or processors across Europe. <a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/accountability-tools\/certification-mechanisms-seals-and-marks_en\">GDPR certification<\/a> helps organisations demonstrate their compliance with the law and helps people trust the product, service, process or system for which organisations process their data.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:26% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXciCIYC9Yb3gJ-GWGJjNW4nftENacvM7HM7KfArTuSnPAuJ6yNfS-vgYHhyzAxlz9-dRWUgGVaRQQ3fzIZKyPU7h1TvAobhVAxkMmqEO9rQilIG6lPfz8HjihVmHZpfhRz_9c1mdw?key=EOFAZNHnCrCRZL5bYN_PMdGs\" alt=\"DORA application\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>US restricted transfers: <\/strong>The Department of Justice has suggested restrictions on cross-border transfers of sensitive personal data to <a href=\"https:\/\/www.jdsupra.com\/legalnews\/doj-seeks-to-restrict-data-transfers-to-5451025\/\">&#8220;countries of concern&#8221;<\/a>. The regulation would, among other things, restrict data brokerage transactions that pose significant national security threats to China, Russia, Iran, North Korea, Cuba, and Venezuela, and limit some vendor, employment, and investment arrangements with nations of concern unless they fulfil specified security standards.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>Those adversaries can be interested in <a href=\"https:\/\/www.justice.gov\/d9\/2024-10\/nsd_104_-_data_security_-_1124-aa01_-_notice_of_proposed_rulemaking_0.pdf\">biometric and genomic data, health care data, geolocation information, vehicle telemetry information, mobile device information, financial transaction data, and data on individuals\u2019 political affiliations<\/a> and leanings, hobbies, and interests. In this way, countries of concern can exploit their access to US government-related data or Americans\u2019 bulk sensitive personal data to collect information on activists, academics, journalists, dissidents, and political figures.&nbsp;<\/p>\n\n\n\n<p><strong>Oregon and several other US states <\/strong>have recently advanced their privacy laws<strong>. <\/strong>For instance, the <a href=\"https:\/\/www.doj.state.or.us\/consumer-protection\/id-theft-data-breaches\/privacy\/\">Oregon Consumer Privacy Act<\/a> applies to all for-profit businesses immediately and to applicable charitable organisations as of 1 July 2025. It provides residents with an opt-out option to a business selling, profiling, and using targeted advertising with their personal information, obtaining a copy, editing any inaccuracies and deleting the personal and sensitive data a business has collected about them.<\/p>\n\n\n\n<p>On January 1, 2025, five more states\u2019 consumer privacy rights laws will take effect &#8211; <a href=\"https:\/\/www.jdsupra.com\/legalnews\/five-states-consumer-privacy-rights-5788949\/\">Iowa, Delaware, New Hampshire, Nebraska, and New Jersey<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Customer expectations about their data<\/strong><\/h4>\n\n\n\n<p>The assessment of customer expectations regarding the processing of their data is an essential element in ensuring the lawfulness and transparency of data processing states the Latvian regulator. Reasonable expectations are what a customer, given their specific relationship with the organisation, types of data and available information, can naturally expect from the processing of their data. A practical approach to assessing expectations would be conducting surveys, <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-klienta-gaidu-novertejums-par-savu-datu-apstradi\">interviews and focus group discussions, as well as consulting industry standards and previous experience<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Internal procedures and training<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text has-media-on-the-right is-stacked-on-mobile\" style=\"grid-template-columns:auto 26%\"><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>Developing appropriate internal procedures and regular training also helps ensure employees know how to act in supporting the company&#8217;s compliance efforts. This may be especially useful when a business expands rapidly, hires new employees, and the number of clients also increases. If <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dvi-skaidro-kapec-jaizstrada-kartiba-ieksejo-procesu-uzraudzibai-un-ricibas-plans-neatbilstibu-konstatesanas-gadijuma\">non-compliance is detected which could result in a violation of customer data processing and protection<\/a>, the company, with the help of its <a href=\"https:\/\/techgdpr.com\/blog\/dpo-appointment\/\">data protection specialist<\/a>, has to prepare an action plan, which may include:<\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXePSZoFgAaa7tAMB21yDzc0kPQkCGK5wCGlzjlO9zZGpL5sc_Bwp4ypRwYe2VcW-i2K0blQoHsWE_N0lQXOhZXdv6xP6te17_WviZdWaOxVhPZda3BHOfU3T2bkMuf5Q8IrzFreYQ?key=EOFAZNHnCrCRZL5bYN_PMdGs\" alt=\"DORA application\" \/><\/figure><\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li>conducting internal audits,&nbsp;<\/li>\n\n\n\n<li>reporting immediately to the responsible person,&nbsp;<\/li>\n\n\n\n<li>reviewing and improving legal bases and purposes of processing,<\/li>\n\n\n\n<li>reviewing related documentation,<\/li>\n\n\n\n<li>corrective measures such as informing data subjects, etc.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<p><strong>Machine learning and training data: <\/strong>America\u2019s NIST continues its series of posts about privacy-preserving federated learning, (PPFL). Unlike traditional centralised learning, PPFL solutions prevent the organisation training the model from looking at the training data. Model training is, however, only a small part of the machine learning workflow. In practice, data scientists spend a lot of time on data preparation and cleaning, handling missing values, feature construction and selection. Challenges may result from <a href=\"https:\/\/www.nist.gov\/blogs\/cybersecurity-insights\/data-pipeline-challenges-privacy-preserving-federated-learning\">poor-quality or maliciously crafted data to intentionally reduce the quality of the trained mode<\/a>l.&nbsp;<\/p>\n\n\n\n<p>To know more about AI model training the Spanish regulator AEPD has recently discussed a use case: <a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/blog\/datos-e-informacion-en-inteligencia-artificial\">a single-neuron network determines whether a person is overweight<\/a> vs a network, which allows for more complex classifications but equally can lead to \u2018hallucinations\u2019. From a data protection perspective, the question is to choose the one that is most appropriate to the context and purpose of the processing operation. For example, the chosen structure&nbsp; requires such a quantity of data samples and such diversity that it is not possible to obtain them, or that it is not proportional or legitimate to collect them. In this way, the purpose could not be achieved from the design stage.&nbsp;<\/p>\n\n\n\n<p><strong>Software developers: <\/strong>Italian regulator Garante approved the <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/10076607#4\">Code of Conduct<\/a> which concerns the processing of personal data carried out by companies developing and producing management software. Such software, intended for companies, associations, professionals and public administrations, is used to <a href=\"https:\/\/www.garanteprivacy.it\/web\/guest\/home\/docweb\/-\/docweb-display\/docweb\/10077212\">fulfil tax and social security, welfare and management obligations, drafting financial statements, personnel management and corporate obligations<\/a>, with a significant impact on aspects relating to the protection of personal data.&nbsp;<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_b01d71970ea064e7a9fafc3a55363ec6\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Sky Italia telemarketing fine<\/strong><\/h4>\n\n\n\n<p>The Italian regulator also fined <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/10076607\">Sky Italia over 840 thousand euros<\/a> for numerous violations found during telemarketing activities and sending commercial communications. The company carried out marketing activities, by telephone and via SMS, in the absence of adequate checks on the obligations regarding information and consent. Sky did not consult the registration of the users contacted in the public register of oppositions before each promotional campaign.<\/p>\n\n\n\n<p>Some of the users had been contacted based on consent acquired even before the GDPR came into full effect. The documentation of consents acquired from data supply companies also appeared unsuitable to unequivocally demonstrate the will of the interested parties, as Sky stored the details of the consents in editable Excel files. Furthermore, Sky relied on the <a href=\"https:\/\/www.garanteprivacy.it\/web\/guest\/home\/docweb\/-\/docweb-display\/docweb\/10076504\">consent to marketing automatically provided by users during registration on the website<\/a> and mandatory to use the service offered.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More enforcement decisions<\/h4>\n\n\n\n<p>The Irish Data Protection Commission <strong>fines Meta 251 million euros<\/strong>. Investigations were launched following a personal data breach, which was reported by Meta in September 2018. It impacted approximately 29 million Facebook accounts globally, of which approximately 3 million were based in the EU\/EEA.&nbsp;The categories of personal data affected included the user\u2019s full name, email address, phone number, location, place of work, date of birth, religion, gender, posts on timelines, groups of which a user was a member, and children\u2019s personal data. The <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/press-releases\/irish-data-protection-commission-fines-meta-eu251-million#_ftn1\">breach arose from the exploitation by unauthorized third parties of user tokens on Facebook<\/a>. <\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:26% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXefUvjufrki198WNFbW8EXVLVhUWEGWfU7arwOI6B7XADNLtnEZKYiEB_D6EQPyjwOGP8qmI3L9GLC_e0-sIMnlhGbGKF8JhaZdTDXikoDvwzVyin7S1mGtacXLDMx8QRjq9cQe?key=EOFAZNHnCrCRZL5bYN_PMdGs\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>CCTV: <\/strong>The Swedish data protection authority fined Granit Bostad Beritsholm AB due to <a href=\"https:\/\/www.imy.se\/nyheter\/sanktionsavgift-mot-bostadsbolag-for-otillaten-kamerabevakning\/\">unauthorized camera surveillance in an apartment building<\/a>.&nbsp; Previously there were cameras at three main entrances, at elevators and apartment doors, as well as in the basement corridor next to the storage room, laundry room and sauna. There were also several cameras in the garage, bicycle storage, garbage room, and at the back of the property. <\/p>\n<\/div><\/div>\n\n\n\n<p>The company now has to cease the camera surveillance of all places on the property except the garage. The camera <a href=\"https:\/\/www.imy.se\/globalassets\/dokument\/beslut\/2024\/beslut-tillsyn-granit-bostad-beritsholm.pdf\">signs must contain information about the company&#8217;s identity and contact information<\/a>.<\/p>\n\n\n\n<p><strong>Prison sentence: <\/strong>A motor insurance worker, who led a team dealing with accident claims, has been handed a suspended prison sentence after an investigation by the UK Information Commissioner. The company reported to the regulator that it suspected an <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/12\/manchester-employee-handed-suspended-prison-sentence-for-illegally-accessing-personal-information\/\">employee was unlawfully accessing its systems<\/a>. The insurers became suspicious due to the higher-than-normal number of claims being processed. An internal investigation found he had featured in 160 of the claims, despite his role not involving the access of claims. The search of the suspect\u2019s home also found he was sending personal data he had accessed by mobile phone to another person.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>AI impact assessment<\/strong><\/h4>\n\n\n\n<p>The Future of Privacy Forum has prepared a detailed guide on how organisations can <a href=\"https:\/\/fpf.org\/wp-content\/uploads\/2024\/12\/FPF-AI-Governance-Behind-the-Scenes-2024.pdf\">conduct AI impact assessments.<\/a> Organisations typically take four common steps: a) initiating an AI impact assessment; b) gathering model and system information; c) assessing risks and benefits; and d) identifying and testing risk management strategies. There is also a trend within organisations to perform multiple assessments at different points in the AI lifecycle, as well as integrate AI impact assessments into <a href=\"https:\/\/fpf.org\/wp-content\/uploads\/2024\/12\/FPF-AI-Governance-Behind-the-Scenes-2024.pdf\">existing risk management processes, including those around privacy<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Real-Time Bidding<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text has-media-on-the-right is-stacked-on-mobile\" style=\"grid-template-columns:auto 26%\"><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>America\u2019s FTC announced a new enforcement action in which it alleged that the data broker Mobilewalla collected and <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2024\/12\/ftc-takes-action-against-mobilewalla-collecting-selling-sensitive-location-data\">retained sensitive location information from consumers, often without their consent<\/a>, and shared those details with third parties to target advertisements.  Most of the advertisements we see online often involve a process called \u201creal-time bidding\u201d, (RTB), where publishers, websites, apps, or other digital mediums with ad space to sell, <a href=\"https:\/\/www.ftc.gov\/policy\/advocacy-research\/tech-at-ftc\/2024\/12\/unpacking-real-time-bidding-through-ftcs-case-mobilewalla\">auction off their empty ad space on exchange platforms<\/a>, and advertisers can bid for that placement.<\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXey9ZF3JL0DTkfcBdBKlUeEGqiVNoG02ddNhsO2Oj5IGLJ82hS-CbvRrQJHQMqU88VSIkr62184s3JaLBn2EFyC-L9yYcfzpenfjK-pOps2EOToYFkyYm4yeBH9dMN-vgXBRk75yw?key=EOFAZNHnCrCRZL5bYN_PMdGs\" alt=\"\" \/><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Big Tech<\/h4>\n\n\n\n<p><strong>LinkedIn suspended AI training in Canada: <\/strong>The Privacy Commissioner welcomed the commitment from <a href=\"https:\/\/www.priv.gc.ca\/en\/opc-news\/news-and-announcements\/2024\/nr-c_241210b\/\">LinkedIn to pause training of AI models<\/a> using the personal information from Canadian member accounts. While LinkedIn indicated that it believed that it had implemented its AI model in a privacy-protective manner, the company agreed to engage in discussions with the regulator to ensure that its practices are compliant with <a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/pipeda_brief\/\">Canada\u2019s federal private-sector privacy law<\/a>.<strong> <\/strong>Recently LinkedIn also suspended AI training using UK and EU data.&nbsp;<\/p>\n\n\n\n<p><strong>The European Data Protection Supervisor<\/strong> is examining the Commission\u2019s compliance regarding the <a href=\"https:\/\/www.edps.europa.eu\/press-publications\/press-news\/press-releases\/2024\/edps-follows-compliance-european-commissions-use-microsoft-365_en\">use of Microsoft 365<\/a>. The Commission could have infringed several provisions of the data protection law for EU institutions, bodies, offices and agencies, including those on transfers of personal data outside the EU\/EEA. In its decision of March 2024, the EDPS ordered the <a href=\"https:\/\/www.edps.europa.eu\/data-protection\/our-work\/publications\/investigations\/2024-03-08-edps-investigation-european-commissions-use-microsoft-365_en\">Commission to suspend all data flows<\/a> resulting from its use of Microsoft 365 to Microsoft and its affiliates and sub-processors, located in countries outside Europe not covered by an adequacy decision. There is also an ongoing court proceeding in the matter.&nbsp;<\/p>\n\n\n\n<p><strong>AI development: <\/strong>The UK Information Commissioner is urging Generative AI developers to <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/12\/generative-ai-developers-it-s-time-to-tell-people-how-you-re-using-their-information\/\">tell people how they\u2019re using their data<\/a>. This could involve providing accessible and specific information that enables people and publishers to understand what personal data has been collected. Without better transparency, it will be hard for people to exercise their information rights and for developers to use legitimate interests as their lawful basis. The Commissioner also encourages AI firms to get advice from the regulator through the <a href=\"https:\/\/ico.org.uk\/for-organisations\/advice-and-services\/regulatory-sandbox\/\">Regulatory Sandbox<\/a>\u202fand <a href=\"https:\/\/ico.org.uk\/for-organisations\/advice-and-services\/innovation-advice\/\">Innovation Advice<\/a>\u202fservices, as well as from other regulators through the <a href=\"https:\/\/www.drcf.org.uk\/ai-and-digital-hub\/\">DRCF AI &amp; Digital Hub.<\/a>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this issue, we explore the DORA application deadline and its interference with the GDPR; how to conduct an AI impact assessment or integrate it into your existing privacy risk management processes; what constitutes US-restricted data transfer to countries of concern; and what expectations customers have about their data; a Real-Time Bidding explainer; a Sky [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":9931,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[51,198,334,35,79,264,38,254],"class_list":["post-9918","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-artificial-intelligence","tag-cctv","tag-dora","tag-gdpr","tag-international-transfers","tag-machine-learning","tag-marketing","tag-meta"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg",1280,754,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-300x177.jpg",300,177,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-768x452.jpg",640,377,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-1024x603.jpg",640,377,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg",1280,754,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg",1280,754,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>In this issue, we explore the DORA application deadline and its interference with the GDPR; how to conduct an AI impact assessment or integrate it into your existing privacy risk management processes; what constitutes US-restricted data transfer to countries of concern; and what expectations customers have about their data; a Real-Time Bidding explainer; a Sky Italia telemarketing fine; and a new Meta privacy violation. Stay up to date! Sign on to receive our fortnightly digest via email. DORA application deadline As the Digital Operational Resilience Act will apply from 17 January 2025, the European supervisors have called on financial entities&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg",1280,754,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-300x177.jpg",300,177,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-768x452.jpg",640,377,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-1024x603.jpg",640,377,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg",1280,754,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg",1280,754,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>In this issue, we explore the DORA application deadline and its interference with the GDPR; how to conduct an AI impact assessment or integrate it into your existing privacy risk management processes; what constitutes US-restricted data transfer to countries of concern; and what expectations customers have about their data; a Real-Time Bidding explainer; a Sky Italia telemarketing fine; and a new Meta privacy violation. Stay up to date! Sign on to receive our fortnightly digest via email. DORA application deadline As the Digital Operational Resilience Act will apply from 17 January 2025, the European supervisors have called on financial entities&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 1 - 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: DORA application deadline, new Meta fine, AI impact assessment\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 1 - 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: DORA application deadline, new Meta fine, AI impact assessment\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-12-18T09:37:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-12-18T13:20:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 1 &#8211; 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment\",\"datePublished\":\"2024-12-18T09:37:58+00:00\",\"dateModified\":\"2024-12-18T13:20:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/\"},\"wordCount\":1906,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/calculator-385506_1280.jpg\",\"keywords\":[\"Artificial Intelligence\",\"CCTV\",\"DORA\",\"GDPR\",\"International transfers\",\"machine learning\",\"marketing\",\"Meta\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/\",\"name\":\"Data protection digest 1 - 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/calculator-385506_1280.jpg\",\"datePublished\":\"2024-12-18T09:37:58+00:00\",\"dateModified\":\"2024-12-18T13:20:13+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: DORA application deadline, new Meta fine, AI impact assessment\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/calculator-385506_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/calculator-385506_1280.jpg\",\"width\":1280,\"height\":754,\"caption\":\"DORA application\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 1 &#8211; 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 1 - 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: DORA application deadline, new Meta fine, AI impact assessment","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 1 - 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: DORA application deadline, new Meta fine, AI impact assessment","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/","og_site_name":"TechGDPR","article_published_time":"2024-12-18T09:37:58+00:00","article_modified_time":"2024-12-18T13:20:13+00:00","og_image":[{"width":1280,"height":754,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 1 &#8211; 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment","datePublished":"2024-12-18T09:37:58+00:00","dateModified":"2024-12-18T13:20:13+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/"},"wordCount":1906,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg","keywords":["Artificial Intelligence","CCTV","DORA","GDPR","International transfers","machine learning","marketing","Meta"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/","name":"Data protection digest 1 - 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg","datePublished":"2024-12-18T09:37:58+00:00","dateModified":"2024-12-18T13:20:13+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: DORA application deadline, new Meta fine, AI impact assessment","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/calculator-385506_1280.jpg","width":1280,"height":754,"caption":"DORA application"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18122024-dora-application-deadline-new-meta-fine-ai-impact-assessment\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 1 &#8211; 15 Dec 2024: DORA application deadline, new Meta fine, AI impact assessment"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=9918"}],"version-history":[{"count":20,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9918\/revisions"}],"predecessor-version":[{"id":9974,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9918\/revisions\/9974"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/9931"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=9918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=9918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=9918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}