Site icon Privacy Desk

Issue 108

Enforcement updates

Dutch Data Protection Authority issues fine on Minister of Finance for violating GDPR 

The Dutch Data Protection Authority (DPA) imposed a fine of EUR 2,750,000 for illegal and discriminatory processing of dual nationality status of Dutch nationals by tax authorities and violation of the General Data Protection Regulation (GDPR). The tax authorities had been keeping and using the data on dual nationality for assessing applications for childcare allowance. The DPA noted that the tax authorities were in serious violation of the GDPR for processing the dual nationality of applicants for childcare allowance in a discriminatory, unlawful, and improper manner.

Canadian Privacy Commissioner announces orders against Clearview AI’s facial recognition technology

The Office of the Privacy Commissioner of Canada announced that the Information and Privacy Commissioners of British Columbia and Alberta and the Quebec Commission on Access to Information issued orders against Clearview AI Inc. after a joint investigation on the company’s facial recognition technology. The company was allegedly collecting images and making facial recognition technology available to law enforcement agencies for identifying individuals without obtaining their consent which violated   private sector privacy laws of the provinces.  The provincial orders ordered Clearview AI to stop its facial recognition services that were subject to this investigation in British Columbia, Alberta, and Quebec.

Clearview AI ordered to cease collecting data from French data subjects

The French Data Protection Authority (CNIL) ordered Clearview AI Inc. to stop collecting and using data collected from data subjects in France and comply with their requests for violating the GDPR. CNIL received complaints from individuals regarding the company’s facial recognition software and initiated an investigation into the same. CNIL found that Clearview AI did not have any legal basis for collecting photographs that support its software from the individuals and failed to facilitate the data subject’s right of access.  

Dating App, Grindr fined by Norway’s Data Protection Authority

Norwegian Data Protection Authority imposed a fine of NOK 65,000,000 on Grindr LLC for violating the GDPR. The Norwegian Consumer Council complained that Grindr, a location-based dating app targeted towards individuals identifying as LGBTQ+, had disclosed the GPS locations, IP addresses, age, gender, and mobile phone advertising tags of users to third parties for marketing purposes. The Data Protection Authority found that the company did not specifically seek user consent for disclosure of personal data to third parties for marketing purposes and information on disclosure was not clear or accessible enough for its users.

Guidance updates

Regulatory updates around the globe 

US updates

EU updates

India updates

News around the globe

Big tech updates

Read our digital newsletter here.


© 2019 Reina Consulting LLP – All rights reserved

Exit mobile version