FPF Releases New Report on GDPR Guidance for US Higher Education Institutions
Today, FPF released The General Data Protection Regulation: Analysis and Guidance for US Higher Education Institutions by Senior Counsel Dr. Gabriela Zanfir-Fortuna. The new report contains analysis and guidance to assist United States-based higher education institutions and their edtech service providers in assessing their compliance with the European Union’s General Data Protection Regulation (GDPR).
Tech Talk with the Regulators – Understanding Anonymization Under the GDPR
The General Data Protection Regulation (GDPR) has already been in existence for four years, and has been in force for two years. How can anonymization techniques under the GDPR help Data Protection Officers (DPOs) assess innovation? I hosted a webinar with Truata that featured experts from DPAs in Italy, Ireland, and the UK to find […]
FPF CEO: Will I Install an Exposure Notification App? Thoughts on the Apple-Google API
As a privacy expert, if my local health department develops a mobile app for people with a COVID diagnosis to alert anyone they were near, will I use it? Yes, I will. And I will urge friends, neighbors and colleagues to download such an app. I have an immuno-compromised family member in my household. I am […]
FPF Charts DPAs’ Priorities and Focus Areas for the Next Decade
The Future of Privacy Forum (FPF) today released a white paper, New Decade, New Priorities: A summary of twelve European Data Protection Authorities’ strategic and operational plans for 2020 and beyond, that provides guidance on the priorities and focus areas that are considered top concerns amongst European Data Protection Authorities (DPAs) for the 2020s and […]
European Union’s Data-Based Policy Against the Pandemic, Explained
Benefitting from a mature and largely harmonized data protection legal framework, the European Union and its Member States are taking policymaking steps towards a pan-European approach to enlisting data and technology against the spread of COVID-19 and to support the gradual restarting of the economy. Here is an overview of key recent events essential to […]
Why Data Protection Law Is Uniquely Equipped to Let Us Fight a Pandemic with Personal Data
Data protection law is different than “privacy”. We, data protection lawyers, have been complacent recently and have failed to clarify this loud and clear for the general public. Perhaps happy to finally see this field of law taking the front stage of public debate through the GDPR, we have not stopped anyone from saying that […]
A Closer Look at Location Data: Privacy and Pandemics
In this series, Privacy and Pandemics, the Future of Privacy Forum explores the challenges posed by the COVID-19 crisis to existing ethical, privacy, and data protection frameworks, and will seek to provide information and guidance to companies and researchers interested in responsible data sharing to support public health response. Future posts will examine pandemic-tracking mobile […]
EU DPAs Issue Green and Red Lights for Processing Health Data During the COVID-19 Epidemic
As Europe is grappling with an exponential increase in COVID-19 cases, some European Data Protection Authorities issued public interest guidance on the limits of collecting, sharing and using personal data relating to health in these exceptional circumstances. Particular areas of concern are related to the breadth of measures that employers can legally take to monitor […]
Close to the Finish Line: Observations on the Washington Privacy Act
By: Stacey Gray and Gabriela Zanfir-Fortuna * We wrote last week that Washington State seems poised to become the second US state to pass a major comprehensive privacy bill. The proposed Washington Privacy Act (WPA) would be mostly aligned with the EU’s GDPR, the global gold standard for data protection (although there are still some […]
EDPB Draft Guidelines on Connected Cars Focus on Data Protection by Design and Push for Consent
By Gabriela Zanfir-Fortuna and Chelsey Colbert The European Data Protection Board recently published its draft Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications, which are open for feedback until March 20. The EDPB writes that the main challenge for complying with European data protection and privacy laws […]