Site icon Privacy Desk

Issue 129

Enforcement updates

A class-action lawsuit has been brought against Snapchat’s parent company, alleging violation of Illinois’ Biometric Information Privacy Act (BIPA) by illegally collecting users’ biometric information without their consent. Snapchat collected, stored and shared users unique facial features and voices without the required disclosures about how the information will be used and for how long. They also failed to obtain a written release from users authorizing the company’s collection of their private information as required by the BIPA.

The Spanish Data Protection Agency (AEPD) has fined Google LLC for transferring data to third parties without legal base and hindering citizens’ right to erasure constituting a violation under GDPR. The AEPD found that Google LLC sent information of requests made to it by citizens, including their identification, e-mail address, the reasons given, and the URL claimed to the Lumen Project. The AEPD has ordered Google to inline policies and procedures with data protection rules and delete all personal data that have been the subject of a request for the right of erasure. 

The Italian data protection authority (Garante) has imposed two penalties of EUR 2 million and 120 thousand each, on Uber B.V. with registered office in Amsterdam, and Uber Technologies Inc, with registered office in San Francisco, for processing unsuitable information, processing data without consent and failure to notify the Authority upon data breach. Garante thus sanctioned the Dutch company Uber BV and the US Uber Technologies, as joint data controllers, each responsible for violations committed against the over 1 and a half million aggrieved Italian users.

Statements issued

Reports published

Regulatory updates around the world

EU updates

UK updates

US updates

India updates

News around the globe

Big Tech updates

Read our digital newsletter here.

Exit mobile version