20th Newsletter -> 19 – 25 November 2016

Bavarian DPA Issued a Fine for DPO Conflict of Interests


The Bavarian Data Protection Authority issued a fine for a conflict of interests to a company that appointed internal Data Protection Officer, who at the same time also acted as the IT manager of the company. The DPA stated that the position of an IT manager is not compatible with the position of the DPO since the DPO would monitor himself (e.g. whether his activities as IT manager are in compliance with the data protection law). 

The German Federal Data Protection Act (FDPA) requires companies to appoint a DPO if at least 10 persons are involved in the automated processing of personal data. The FDPA gives companies an option to appoint an employee of the company as an internal DPO or may appoint a professional data privacy advisor as an external DPO. The Bavarian DPA informed the company about the conflict of interest and repeatedly requested the company to appoint a new DPO. The company did not comply with the DPA requests and thus the DPA imposed a fine, the amount of which is unknown.


Read more HERE


Read the Bavarian DPA’s Press Release HERE


___________________________________________________________________


Italian DPA Published Guidance on how to Teach and Respect Privacy in Schools


The purpose of the guidance booklet is to help students, families, teachers and schools navigate the world of data protection. The booklet first explains the concepts of teaching and respecting privacy in schools and it then continues describing the most frequently addressed  cases by the DPA in order to provide guidance regarding the many questions posed by families and institutions alike. The booklet answers questions such as how to process students' (sensitive) personal data lawfully, what rules should be followed to publish personal data on school websites or to disclose those data to families, how to use tablets and smartphones appropriately, what safeguards should be in place regarding the data of students with learning disabilities, etc.


Read more HERE


Read the Guidance Booklet HERE (in Italian)


___________________________________________________________________


First 100 Days for the UK Information Commissioner


Elizabeth Denham had been appointed as a UK Information Commissioner more then 100 days ago and at the recent convention she talked about the challenges of her role during her speech. Most importantly she also talked about the topic of the GDPR and the uncertainty surrounding the UK implementing it following the Brexit vote.


Read more HERE


Read Ms. Dunham’s Speech HERE


___________________________________________________________________


Bavarian DPA Issues Guidance on Processing of personal data for advertising


This week the Data Protection Authority of Bavaria issued a short paper on processing of personal data for the purposes of advertising. They have done so because the GDPR does not include the detailed regulations. Furthermore, in the future the legal basis for the assessment of the admissibility of advertising will be, apart from a legitimate consent, weighing of interests according to Art. 6 (1)(f) GDPR.


Read more HERE


Read the Short Paper HERE


___________________________________________________________________

Compiled by Jernej Mavrič, email: jm@dp-recruitment.com 

___________________________________________________________________

Follow us on Twitter @LastWeekInPDP  and visit our WEBSITE

For privacy jobs and vacancies follow @dprecruitment