European data regulators issued EUR2.92 billion in GDPR fines last year – a 168% increase on the previous year, according to global law firm DLA Piper
30 Ianuarie 2023 BizLawyer
• European data protection supervisory authorities have issued EUR1.64 billion since 28 January 2022, a 50% increase against the previous year • This year’s highest fine of EUR 405 million was imposed by the Irish Data Protection Commissioner against Meta Platforms Ireland Limited relating to Instagram for various alleged failures to protect children’s personal data. • The average number of notified data breaches per day fell slightly from 328 notifications per day to 300 notifications per day suggesting that organisations might be becoming warier of notifying breaches for fear of investigations, fines and compensation claims. The Netherlands remains at the top of the table for the number of breach notifications made per 100,000 capita • Luxembourg remains at the top of the country league table for the highest GDPR fine imposed since 25 May 2018: a fine of EUR 746 million. But Ireland is catching up, taking the 2nd, 3rd, 4th, 5th and 6th places in the country fines league table after a very busy year for the DPC
| |
Global law firm DLA Piper has today published the findings of its annual GDPR and Data Breach Survey. The Europe-wide survey has revealed another record year with a 50% year on year increase in the total value of fines issued across Europe.
Among the largest fines levied were those against Meta Platforms Ireland Ltd. (Meta) demonstrating that social media, and its reliance on extensive processing of personal data, have been a particular focus of regulatory action. Several of the largest fines imposed against Meta this year by the Irish DPC relate to Facebook and Instagram’s behavioral profiling of users and whether the lawful basis of “contract necessity” can be used to legitimise the mass harvesting of personal data. While the Irish DPC originally concluded that this was possible, the influential European Data Protection Board disagreed. The resulting fines raise serious questions about the grand bargain struck between consumers and service providers, and how “free” online services will be funded going forward. Given what is at stake, DLA Piper expects these decisions to be appealed and years of subsequent litigation.
The survey also reveals a year which saw the volume of data breaches notified to supervisory authorities decrease slightly against the previous year’s total. The average daily total dropped from 328 notifications per day to 300 per day this year. This may in part be a sign that organisations are becoming more wary of notifying data breaches to regulators for fear of investigations, fines and compensation claims.
While personal data issues around advertising and social media have dominated headlines this year, there is a growing focus on Artificial Intelligence, and the role of personal data used to train AI. Most prominently this year multiple investigations into facial recognition company Clearview AI took place following complaints by digital rights organisations, including Max Schrems’s organisation My Privacy is None of your Business (NOYB) with several fines issued. As AI and machine learning platforms continue to become more ubiquitous, the survey predicts more regulatory investigations and enforcement for the year ahead with a focus on both providers and users of AI.
The survey also reports some notable decisions made by data protection supervisory authorities this year considering the application of the Schrems II and Chapter V GDPR requirements to specific international transfers of personal data. Data protection supervisory authorities have argued that it is not possible to adopt a risk-based approach when assessing transfers of personal data to “third countries”, in essence arguing that transfers are prohibited if the mere possibility of foreign governmental access gives rise to any risk of harm (however trivial and however unlikely).
Commenting on the survey, Irina Macovei, Counsel at DLA Piper said: “DLA Piper’s annual survey is a key tool for privacy professionals to understand trends in enforcement of data protection – as disappointing or intriguing such trends may be – and a great support tool in communicating effectively such trends to key stakeholders. It is an overview that shows, time and time again, that national particularities must always be factored in, although we refer to a EU regulation”.
“I am particularly worried about the absolutist interpretation of GDPR's data transfer rules exhibited by certain supervisory authorities over the course of last year” added Andrei Stoica, Senior Associate. “Not only does this approach arguably collide with the proportionality principle under EU law, but it may also hinder the legitimate flow of information from and to Europe, discourage innovation and ultimately slow down progress. I certainly hope that 2023 will see a shift in attitude towards such transfers.”
| Publicitate pe BizLawyer? |
![]() ![]() |
| Articol 801 / 4593 | Următorul articol |
| Publicitate pe BizLawyer? |
![]() |
Wolf Theiss a asistat Rheinmetall în legătură cu semnarea unui acord de înființare a unui joint venture cu Pirochim Victoria
Într-un an cu investigații mai tehnice și presiune pe termene, DLA Piper România așază practica de Concurență pe trei piloni - oameni, metodă, ritm, astfel încât proiectarea strategiilor, controlul probelor și continuitatea între faze să producă cele mai bune rezultate | De vorbă cu membrii unei echipe sudate, condusă de lideri cu experiență și antrenată pe industrii sensibile, despre prudență juridică și curaj tactic, cooperare internă și rigoare probatorie, bazate pe înțelegerea fină a mediului de business și utilizarea tehnologiei ca multiplicator de acuratețe
Filip & Company a oferit asistență juridică în legătură cu o nouă emisiune de obligațiuni corporative garantate de către Agroserv Măriuța, în valoare de 3 mil. €
Kinstellar asistă Integral Capital Group în achiziția unei participații majoritare la clinica de fertilizare in vitro Calla, prin subsidiara sa Embryos
Filip & Company a asistat consorțiul de bănci care a intermediat a doua emisiune de obligațiuni prin care Romgaz a atras 500 de mil. € de pe piețele internaționale| Alexandru Bîrsan (managing partner) și Olga Niță (partener) au coordonat echipa
Filip & Company a asistat BCR și BRD în legătură cu oferta publică inițială a Cris Tim Family Holding | Olga Niță (partener) și Alexandru Bîrsan (managing partner) au coordonat echipa
Clifford Chance Badea a asistat Cris-Tim Family Holding în legătură cu IPO-ul istoric în valoare de 454,35 milioane RON | Daniel Badea (Managing Partner): ”Sperăm ca succesul Cris-Tim să încurajeze și alte branduri românești să vină pe bursă”
Filip & Company a asistat DIGI Romania S.A. în legătură cu emisiunea de obligațiuni de 600 mil. €. Alexandru Bîrsan (managing partener) a coordonat echipa
LegiTeam: Zamfirescu Racoţi Vasile & Partners recrutează avocat definitiv Dreptul muncii | Consultanță
LegiTeam: Zamfirescu Racoţi Vasile & Partners recrutează avocat definitiv Real Estate | Consultanță
Țuca Zbârcea & Asociații obține o soluție favorabilă într-un important litigiu de drept fiscal și vamal | Ionuț Șerban (Partener): „Este o victorie importantă pentru clientul nostru și un precedent valoros în disputele de drept vamal”
Avocații PNSA au stat alături de M Plus Croatia d.o.o, lider european în outsourcing-ul proceselor de afaceri și tehnologie, în tranzacția prin care a achiziționat Valoris Group - jucător local care deservește proiecte multilingve pentru clienți internaționali | Echipa pluridisciplinară a fost coordonată de partenerul Bogdan C. Stoica
-
BizBanker
-
BizLeader
- in curand...
-
SeeNews
in curand...









RSS





