GDPR

Su­per­vi­sor Aut­ho­ri­ty: Failure to report a Data Breach

21. Juli 2025|

The Irish Data Pro­tec­tion Com­mis­sio­ner has imposed a fine of EUR 125,000 because a con­trol­ler (the City of Dublin) dis­c­lo­sed per­so­nal data of ap­pro­xi­m­ate­ly 13,000 people without aut­ho­ri­sa­ti­on after a server was at­ta­cked with malware. In ad­di­ti­on to the master [...]

Control ob­li­ga­ti­ons in (chain) data pro­ces­sing: EDPB pro­vi­des clarity

20. Juni 2025|

The Eu­ro­pean Data Pro­tec­tion Board (EDPB) has pu­blished Opinion 22/2024, which pro­vi­des key cla­ri­fi­ca­ti­ons on the data pro­tec­tion control re­spon­si­bi­li­ty of the con­trol­ler in data pro­ces­sing. The state­ments are par­ti­cu­lar­ly im­portant for multi-level con­trac­tu­al re­la­ti­onships and streng­then the role of [...]

GDPR: Fines for in­cor­rect risk assessment

26. Juli 2024|

Fines may be imposed for "in­cor­rect" risk as­sess­ment in the event of a data breach. In the event of a data breach, in ad­di­ti­on to no­ti­fi­ca­ti­on to the data pro­tec­tion su­per­vi­so­ry aut­ho­ri­ty, it may also be ne­ces­sa­ry to notify the [...]

Data pro­tec­tion su­per­vi­so­ry aut­ho­ri­ty clears up data pro­tec­tion misconceptions

11. April 2024|

The Thu­rin­gi­an State Com­mis­sio­ner for Data Pro­tec­tion and Freedom of In­for­ma­ti­on (TLfDI) has used Safer In­ter­net Day 2024 to clarify per­sis­tent data pro­tec­tion mis­con­cep­ti­ons. Here are a few mis­con­cep­ti­ons: Data pro­tec­tion wants to prevent di­gi­ta­li­sa­ti­on No. Di­gi­ta­li­sa­ti­on, but legally compliant [...]

Pre­pa­ra­ti­on is ever­y­thing: How to prepare for a cyberattack

28. März 2024|

Cyber attacks can affect any company, often oc­cur­ring when least ex­pec­ted, rang­ning from data loss and fi­nan­cial set­backs to a per­ma­nent­ly damaged re­pu­ta­ti­on. How you can prepare your company?  Crea­ti­on of an in­ci­dent re­spon­se plan An In­ci­dent Re­spon­se Plan (IRP) [...]

Nach oben