GDPR: Updating Privacy Notices

Are you caught in a last minute rush to update your privacy notice to comply with the forthcoming General Data Protection Regulation (GDPR)? Under the Data Protection Act 1998 (DPA), the requirement to issue privacy notices is tucked way in Schedule 1 Part 2. The GDPR brings privacy notices into the foreground and introduces a … Continue reading “GDPR: Updating Privacy Notices”

The revised ICO Privacy Notices Code and GDPR

Earlier this month the Information Commissioner’s Office (ICO) published its revised Privacy Notices Code of Practice. Under the Data Protection Act 1998 (DPA), a Data Controller should issue a privacy notice to Data Subjects whenever personal data is gathered from them. This should be done at the point of collection or as soon as reasonably … Continue reading “The revised ICO Privacy Notices Code and GDPR”

Privacy Notices under #GDPR: Have you noticed my notice?

Please also read our updated blog on privacy notices here. As you all know by now the General Data Protection Regulation (GDPR) is here and it is (as predicted) starting to get various people fired up ready for its 2018 implementation date. (Dear reader, it is still relevant despite the Brexit vote.) We’ve been exploring … Continue reading “Privacy Notices under #GDPR: Have you noticed my notice?”

First Two GDPR Enforcement Notices – Lessons Learnt

The Information Commissioner’s Office (ICO) recently served only its second Enforcement Notice for breaches of the GDPR. The first Enforcement Notice was issued in July 2018 against a Canadian company, AggregateIQ Data Services Ltd (AIQ). Strangely it was not published on the ICO’s website but was mentioned in the ICO’s report: “Investigation into the use of … Continue reading “First Two GDPR Enforcement Notices – Lessons Learnt”

A comprehensive Privacy Policy.

I decided to look at Miley Cyrus’s website. Don’t know why. I just picked a teenage pop singer at random. I found however that I couldn’t just look at her website, I had to register before entering her website. I admit that I’m in socio-economic group A++ and age group 55  to 65 so my … Continue reading “A comprehensive Privacy Policy.”

Experian’s GDPR Appeal: Lawfulness, Fairness, and Transparency

On 20th February 2023, the First-Tier (Information Rights) Tribunal (FTT) overturned an Enforcement Notice issued against Experian by the Information Commissioner’s Office (ICO).  This case relates to Experian’s marketing arm, Experian Marketing Services (EMS) which provides analytics services for direct mail marketing companies. It obtains personal data from three types of sources; publicly available sources, … Continue reading “Experian’s GDPR Appeal: Lawfulness, Fairness, and Transparency”

Back To The Future For UK GDPR?

On 3rd October 2022, during the Conservative Party Conference, Michelle Donelan, the new Secretary for State for Digital, Culture, Media and Sport (DCMS), made a speech announcing a plan to replace the UK GDPR with a new “British data protection system”. Just as we are all getting to grips with the (relatively new) UK GDPR, do we want more change … Continue reading “Back To The Future For UK GDPR?”

£1.35 Million GDPR Fine for Catalogue Retailer

On 5th October, the Information Commissioner’s Office (ICO) issued a GDPR Monetary Penalty Notice in the sum of £1,350,000 to Easylife Ltd. The catalogue retailer was found to have been using 145,400 customers personal data to predict their medical condition and then, without their consent, targeting them with health-related products. This latest ICO fine is interesting but not because of the amount involved. … Continue reading “£1.35 Million GDPR Fine for Catalogue Retailer”

ICO Fines “World’s Largest Facial Network”

The Information Commissioner’s Office has issued a Monetary Penalty Notice of £7,552,800 to Clearview AI Inc for breaches of the UK GDPR.  Clearview is a US based company which describes itself as the “World’s Largest Facial Network”. It allows customers, including the police, to upload an image of a person to its app, which is then … Continue reading “ICO Fines “World’s Largest Facial Network””

Act Now in Dubai 

Last week the Act Now team returned from a trip to the United Arab Emirates to promote our Middle East training programme. It was a great opportunity to better understand the UAE privacy framework and the needs of businesses faced with the challenge of implementing new laws (as well as get some sun!)  The Middle … Continue reading “Act Now in Dubai “

%d bloggers like this: