π NOYB filed complaints against Fitbit in Austria, the Netherlands, and Italy. The issue is that Fitbit, now under Google's umbrella, is requiring new users to consent to data transfers outside the EU. π
βοΈ Here are the key points:
β
Data transfers — When creating a Fitbit account in Europe, users are forced to agree to the transfer of their data to countries with different data protection laws, including the US.
β
Highly personal data — Fitbit's privacy policy allows them to share a wide range of personal data, including health-related information. Users can't easily find out which specific data is shared or where it goes.
β
Limited consent withdrawal — To withdraw consent, users have to delete their account, which means losing all their previously tracked workouts and health data. This applies even to premium subscribers.
β
GDPR violation — Fitbit's approach doesn't comply with European privacy law, which states that consent for data transfers should be occasional and non-repetitive… read more
complianceweek.com • 1 min read
π± Swedish insurance giant Trygg-Hansa slapped with a hefty €3M fine by the Swedish DPA for GDPR breaches. π
Here's the scoop: Trygg-Hansa, which merged with Moderna Försäkringar in April 2022, got into hot water due to alleged security flaws. π΅οΈβοΈ These flaws left customer insurance info accessible online.
The Swedish DPA uncovered that data from 650,000 Moderna Försäkringar customers was exposed from Oct 2018 to Feb 2021. A tipster noticed you could access other policyholders' docs just by tweaking a web link! π¬
βοΈ What was at risk? Health, financial data, SSNs, and more. The DPA found Trygg-Hansa didn't have the right tech measures as per GDPR.
π€· Trygg-Hansa's response? They said Moderna Försäkringar fixed the issue pronto. But they admitted their IT security needed a boost… read more
β Social media giant X (Twitter) is about to embark on a journey that promises to enhance user safety and convenience. Here's the scoop:
π€ Biometric data collection — X is gearing up to collect biometric information with user consent. While the exact details are yet to be revealed, this typically includes fingerprints, iris patterns, or facial features. This move could pave the way for passwordless sign-ins.
π Employment history matters — In addition to biometrics, X is also expanding its data collection to include user employment history, educational background, skills, and job search activity. This aligns with X's plan to introduce new job search features and other functionalities.
π‘The updated privacy policy comes into effect on September 29th, 2023, giving us time to understand the implications better… read more
π’ Senior UK Home Office officials wanted to push controversial facial recognition technology, particularly in retail settings. π
π¬ Internal emails reveal the Home Office's push to influence the Information Commissioner’s Office's investigation into Facewatch, a company deploying facial recognition cameras in shops.
π« This move has sparked privacy and human rights concerns, even as the EU seeks to ban such tech in public spaces… read more
π€ OpenAI is under scrutiny once again! A detailed GDPR complaint has been filed, alleging breaches in various dimensions, including transparency and privacy. π
It's not the first time ChatGPT has faced GDPR issues, with Italy's privacy watchdog already raising concerns earlier this year.
The complaint was filed by Lukasz Olejnik, a privacy researcher, who noticed inaccuracies generated by ChatGPT when he requested a biography. Despite his efforts, OpenAI's response didn't meet GDPR requirements.
βοΈ Key takeaways:
β
Concerns about unlawful data processing.
β
Lack of transparency in data processing.
β
Failure to rectify inaccuracies in generated content.
β
Violation of GDPR's data protection by design and default principle… read more
___
Stay tuned for more by π connecting with us on LinkedIn or, better yet, by subscribing to our weekly newsletter. We do our best to select the most interesting and relevant content in our field and deliver it to you in a bite-sized format, so you can stay up to date on topics such as Privacy Management & Compliance.
Photo by Burst