Bavarian DPA Issued a Fine for DPO Conflict of Interests
The Bavarian Data Protection Authority issued a fine for a conflict of interests to a company that appointed internal Data Protection Officer, who at the same time also acted as the IT manager of the company. The DPA stated that the position of an IT manager is not compatible with the position of the DPO since the DPO would monitor himself (e.g. whether his activities as IT manager are in compliance with the data protection law).
The German Federal Data Protection Act (FDPA) requires companies to appoint a DPO if at least 10 persons are involved in the automated processing of personal data. The FDPA gives companies an option to appoint an employee of the company as an internal DPO or may appoint a professional data privacy advisor as an external DPO. The Bavarian DPA informed the company about the conflict of interest and repeatedly requested the company to appoint a new DPO. The company did not comply with the DPA requests and thus the DPA imposed a fine, the amount of which is unknown.
Read more HERE
Read the Bavarian DPA’s Press Release HERE
___________________________________________________________________
Italian DPA Published Guidance on how to Teach and Respect Privacy in Schools
The purpose of the guidance booklet is to help students, families, teachers and schools navigate the world of data protection. The booklet first explains the concepts of teaching and respecting privacy in schools and it then continues describing the most frequently addressed cases by the DPA in order to provide guidance regarding the many questions posed by families and institutions alike. The booklet answers questions such as how to process students' (sensitive) personal data lawfully, what rules should be followed to publish personal data on school websites or to disclose those data to families, how to use tablets and smartphones appropriately, what safeguards should be in place regarding the data of students with learning disabilities, etc.
Read more HERE
Read the Guidance Booklet HERE (in Italian)
___________________________________________________________________
First 100 Days for the UK Information Commissioner
Elizabeth Denham had been appointed as a UK Information Commissioner more then 100 days ago and at the recent convention she talked about the challenges of her role during her speech. Most importantly she also talked about the topic of the GDPR and the uncertainty surrounding the UK implementing it following the Brexit vote.
Read more HERE
Read Ms. Dunham’s Speech HERE
___________________________________________________________________
Bavarian DPA Issues Guidance on Processing of personal data for advertising
This week the Data Protection Authority of Bavaria issued a short paper on processing of personal data for the purposes of advertising. They have done so because the GDPR does not include the detailed regulations. Furthermore, in the future the legal basis for the assessment of the admissibility of advertising will be, apart from a legitimate consent, weighing of interests according to Art. 6 (1)(f) GDPR.
Read more HERE
Read the Short Paper HERE
___________________________________________________________________
Compiled by Jernej Mavrič, email: jm@dp-recruitment.com
___________________________________________________________________
Follow us on Twitter @LastWeekInPDP and visit our WEBSITE
For privacy jobs and vacancies follow @dprecruitment