article thumbnail

Security Compliance & Data Privacy Regulations

eSecurity Planet

Regulatory compliance and data privacy issues have long been an IT security nightmare. And since the EU’s General Data Protection Regulation (GDPR) took effect May 25, 2018, IT compliance issues have been at the forefront of corporate concerns. GDPR-style data privacy laws came to the U.S. PIPL Raises the Bar – And the Stakes.

article thumbnail

GDPR: lawful bases for processing, with examples

IT Governance

Under the EU GDPR (General Data Protection Regulation) , you need to identify a lawful basis before processing personal data. Lawfulness of processing under the GDPR. And, as ever with the GDPR, it’s your record-keeping that will prove essential. First published June 2018. Last updated March 2020. Legal obligations.

GDPR 92
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Britain’s information commissioner fines British Airways for 2018 Hack

Security Affairs

The ICO fined the airline because the company failed in implementing adequate security measures, the company detected the security breach to months later the initial compromise. People entrusted their personal details to BA and BA failed to take adequate measures to keep those details secure.” ” concludes the ICO.

GDPR 112
article thumbnail

GDPR: lawful bases for processing, with examples

IT Governance

What is a lawful basis for processing under the GDPR? Like the Data Protection Act 1998 (DPA 1998) that it superseded, the General Data Protection Regulation (GDPR) sets out six lawful bases for processing personal data. Lawful processing under the GDPR. Do you always need individuals’ consent to process their data?

GDPR 70
article thumbnail

GDPR Italian Implementing Decree Has Been Published

HL Chronicle of Data Protection

101 of 10 August 2018 (the “Decree”) for the national implementation of General Data Protection Regulation (EU) 2016/679 (the “GDPR”) has been published in the Official Journal. Below, a brief summary of the most relevant provisions: PROVISIONS WHICH INTEGRATE THE GDPR. On 4 September, the Legislative Decree no.

GDPR 40
article thumbnail

Weekly podcast: Yahoo hacker sentenced, acoustic DoS attack and GDPR compliance fails

IT Governance

Finally, a week into the GDPR’s application, a number of organisations have been in the news after their efforts to comply with the new law went awry. It will be reporting the incident, as mandated by the GDPR.

GDPR 67
article thumbnail

New Data Protection-Friendly eCommercial Model Clinical Trial Agreements Now Available

HL Chronicle of Data Protection

Despite their intention, requests for changes to the mCTAs had been notably increasing over the past few years, primarily due to the outdated data protection provisions in the templates which did not fully take into account the application of the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018 (DPA).

GDPR 90