Skip to main content
ShareEmailLinkedInXWhatappsFacebook
feedback
Share

Happy New Year 2025!

2 months 3 weeks ago

We thank you all for your support over the previous year. It has been a true pleasure sharing this journey with you. In 2024, we enjoyed significant achievements. Europrivacy suitability for European accreditation was approved by the European Co-operation for Accreditation (EA), several certification bodies completed their successful Europrivacy accreditation, and the first Europrivacy certifications […]

The post Happy New Year 2025! appeared first on Europrivacy Community.

Europrivacy Community

Data Protection Day 2025

3 months 1 week ago
Data Protection Day 2025 matthijs Wed, 12/18/2024 - 16:47 Tue, 01/28/2025 - 12:00

To mark the Data Protection Day, the EDPS, Council of Europe, and CPDP Conferences joined forces to host a one-day event: “CPDP – Data Protection Day: A New Mandate for Data Protection.”

  • When: 28 January 2025
  • Where: European Commission’s Charlemagne, Brussels
  • Format: In-person and online

This year’s conference came at a crucial time as new EU political mandates begin shaping the policy landscape. Discussion focused on the evolving mandate of data protection, particularly its essential role as safeguard of our democratic society against excessive intrusions in the citizens’ privacy by public or private actors.

0
European Data Protection Supervisor

EDPB opinion on AI models: GDPR principles support responsible AI

3 months 1 week ago

Brussels, 18 December - The European Data Protection Board (EDPB) has adopted an opinion* on the use of personal data for the development and deployment of AI models. This opinion looks at 1) when and how AI models can be considered anonymous, 2) whether and how legitimate interest can be used as a legal basis for developing or using AI models, and 3) what happens if an AI model is developed using personal data that was processed unlawfully. It also considers the use of first and third party data.

The opinion was requested by the Irish Data Protection Authority (DPA) with a view to seeking Europe-wide regulatory harmonisation. To gather input for this opinion, which deals with fast-moving technologies that have an important impact on society, the EDPB organised a stakeholders’ event and had an exchange with the EU AI Office.

EDPB Chair Talus said: “AI technologies may bring many opportunities and benefits to different industries and areas of life. We need to ensure these innovations are done ethically, safely, and in a way that benefits everyone. The EDPB wants to support responsible AI innovation by ensuring personal data are protected and in full respect of the General Data Protection Regulation (GDPR).”

Regarding anonymity, the opinion says that whether an AI model is anonymous should be assessed  on a case by case basis by the DPAs. For a model to be anonymous, it should be very unlikely (1) to directly or indirectly identify individuals whose data was used to create the model, and (2) to extract such personal data from the model through queries. The opinion provides a non-prescriptive and non-exhaustive list of methods to demonstrate anonymity.

With respect to legitimate interest, the opinion provides general considerations that DPAs should take into account when they assess if legitimate interest is an appropriate legal basis for processing personal data for the development and the deployment of AI models.

A three-step test helps assess the use of legitimate interest as a legal basis. The EDPB gives the examples of a conversational agent to assist users, and the use of AI to improve cybersecurity. These services can be beneficial for individuals and can rely on legitimate interest as a legal basis, but only if the processing is shown to be strictly necessary and the balancing of rights is respected.

The opinion also includes a number of criteria to help DPAs assess if individuals may reasonably expect certain uses of their personal data. These criteria include: whether or not the personal data was publicly available, the nature of the relationship between the individual and the controller, the nature of the service, the context in which the personal data was collected, the source from which the data was collected, the potential further uses of the model, and whether individuals are actually aware that their personal data is online.

If the balancing test shows that the processing should not take place because of the negative impact on individuals, mitigating measures may limit this negative impact. The opinion includes a non-exhaustive list of examples of such mitigating measures, which can be technical in nature, or make it easier for individuals to exercise their rights or increase transparency.

Finally, when an AI model was developed with unlawfully processed personal data, this could have an impact on the lawfulness of its deployment, unless the model has been duly anonymised.

Considering the scope of the request from the Irish DPA, the vast diversity of AI models and their rapid evolution, the opinion aims to give guidance on various elements that can be used for conducting a case by case analysis.

In addition, the EDPB is currently developing guidelines covering more specific questions, such as web scraping.


Note to editors:
*An Article 64(2) opinion addresses a matter of general application or produces effects in more than one Member State.

EDPB

PATRICIA Exercise 2024 - Personal dATa bReach awareness In Cybersecurity Incident hAndling

3 months 2 weeks ago
PATRICIA Exercise 2024 - Personal dATa bReach awareness In Cybersecurity Incident hAndling matthijs Tue, 12/17/2024 - 12:40 Mon, 12/16/2024 - 12:00

The event, hosted at the EDPS premises in Brussels, aimed to raise awareness among staff from European Union Institutions, Bodies, and Agencies (EUIs) on managing personal data breaches.

1 Read the executive summary of the report
European Data Protection Supervisor

EDPS Campaign on raising awareness of personal data breaches

3 months 2 weeks ago
EDPS Campaign on raising awareness of personal data breaches matthijs Tue, 12/17/2024 - 12:35 Mon, 12/16/2024 - 12:00

In 2024, the European Data Protection Supervisor (EDPS) launched a dedicated campaign to raise awareness of personal data breaches, one of 20 initiatives organised to mark the institution’s 20th Anniversary. The campaign ran from March to October 2024, 

1 Read the executive summary of the report
European Data Protection Supervisor

20 Talks - Carrisa Véliz: Associate Professor at the University of Oxford

3 months 2 weeks ago
20 Talks - Carrisa Véliz: Associate Professor at the University of Oxford matthijs Mon, 12/16/2024 - 16:15 Tue, 12/17/2024 - 12:00

Carissa Véliz is an Associate Professor at the University of Oxford. Prof Véliz graduated in philosophy from the University of Salamanca, completed a master's degree in philosophy at the CUNY graduate centre in New York, and received a doctorate in philosophy from the University of Oxford, where she currently works at the Faculty of Philosophy and the Institute on Ethics of Artificial Intelligence.

1 Watch the episode here!
European Data Protection Supervisor

Newsletter 112

3 months 2 weeks ago
Newsletter 112 julia Mon, 12/16/2024 - 09:58 Mon, 12/16/2024 - 12:00

In this issue, learn about our global efforts to elevate data protection standards, our work on artificial intelligence and more!

Read last newsletter of 2024

0
European Data Protection Supervisor

New episode of 20 Talks is out!

3 months 2 weeks ago
New episode of 20 Talks is out! miriam Wed, 12/11/2024 - 09:42 Thu, 12/12/2024 - 12:00

Today, we welcome Jan Philipp Albrecht. Jan is a co-President of the Heinrich Böll Foundation who shares his expertise on data protection, privacy, and digital rights. 

1 Have a listen
European Data Protection Supervisor

The EDPS follows up on the compliance of European Commission’s use of Microsoft 365

3 months 3 weeks ago
The EDPS follows up on the compliance of European Commission’s use of Microsoft 365 julia Tue, 12/10/2024 - 10:59 Tue, 12/10/2024 - 12:00

The European Data Protection Supervisor (EDPS) is examining the European Commission’s compliance with its decision of 8 March 2024 regarding the use of Microsoft 365. Following its investigation, the EDPS had found that the European Commission infringed several provisions of Regulation (EU) 2018/1725, the EU’s data protection law for EU institutions, bodies, offices and agencies (EUIs), including those on transfers of personal data outside the EU/European Economic Area (EEA).

Read Press Release

0
European Data Protection Supervisor