Site icon Privacy Desk

Issue 124

Enforcement updates

CNIL, the French Data Protection Authority, sanctioned a fine of EUR 1,500,000 on Dedalus Biologie for a massive data leak involving the dissemination of the names, social security numbers, and medical information of 500,000 people. Dedalus is a company that markets software solutions for medical analysis laboratories.

The U.S. Ninth Circuit of Appeals affirmed its earlier preliminary injunction where it held that LinkedIn could not prevent HiQ, a data analytics company, from collecting and using information shared by LinkedIn users on their public profiles. HiQ uses automated bots to scrape information from LinkedIn profiles and sell it to business clients. HiQ argued that letting established entities that accumulate large user data sets determine who may scrape data from public sites would give such entities excessive control over how that data may be used.

The Dutch DPA issued a fine of EUR 565,000 to the Dutch Ministry of Foreign Affairs for serious infringement of GDPR in the process of issuing visas. The digital system used by the Ministry was held inadequately secure and prone to the risk of unauthorized access. Further, the Ministry failed to provide visa applicants with sufficient information on sharing of personal data with third parties.

Guidance updates

Regulatory updates

UK updates

EU updates

US updates

China updates

India updates

News around the globe

Big tech updates

Read our digital newsletter here.


© 2019 Reina Consulting LLP – All rights reserved

Exit mobile version