Photo of Clare Sellars

lockThe European Data Protection Board (EDPB) has updated its Guidelines on GDPR consent to clarify that making access to a website conditional on accepting cookies – so-called “cookie walls” – does not constitute valid consent and that scrolling or swiping through a webpage cannot constitute consent either, under any circumstances.

Updated Guidelines

“Guidelines on consent under Regulation 2016/679” were first published in November 2017 by the EDPB’s predecessor, the Article 29 Working Party, and formally adopted in April 2018. The EDPB has now produced a slightly updated version of those Guidelines which, apart from two important clarifications, essentially remain the same. The clarifications appear in the sections of the Guidelines on “Conditionality” and “Unambiguous indication of wishes” and concern, respectively, the validity of consent provided by individuals when interacting with “cookie walls” and the question of scrolling or swiping through a webpage or similar user activity to indicate consent.
Continue Reading European Data Protection Board Updates Guidelines on GDPR Consent

The use of artificial intelligence and surveillance technology of various kinds is increasingly being used as a weapon in the fight against coronavirus around the world.  Recent examples include the use of facial recognition software in Russia to enforce lockdown restrictions, while in France monitoring software has apparently been trialed with a view to using video surveillance cameras once lockdown has been moderated to determine whether citizens are adhering to social distancing rules and wearing masks.

In recent days it has been reported that various companies are in discussions with the UK Government regarding the use of facial recognition technology in connection with the much discussed concept of so-called “immunity passports”.
Continue Reading The Use of Facial Recognition Technology to Combat COVID-19

In an interesting data protection case, Elgizouli (Appellant) v Secretary of State for the Home Department (Respondent) [2020] UKSC 10, the UK Supreme Court has held that the UK Government breached data protection laws in passing information to US authorities following a mutual legal assistance (MLA) request that could involve the US seeking the death penalty for two men.  The men are alleged to have been members of a terrorist group operating in Syria involved in the torture and murder of hostages.
Continue Reading UK Held to Have Breached Data Protection Laws Over Alleged Islamic State Members

Although data protection and privacy may not be the first things that come to mind when considering how best to wage war against COVID-19, organizations that collect and use personal data and special categories of health-related data to try to combat this gravest of threats to public health should also consider how to ensure that their activities in this regard are reasonable and proportionate in the light of applicable data protection legislation.
Continue Reading Respecting Privacy During the Coronavirus Pandemic

As measures taken by governments around the world to combat the spread of coronavirus continue to intensify, the possible consequences of remote working for your business should be considered.

Whether you are a service provider or a customer, it will be important to try to ensure that ‘business as usual’ can continue and to address any technical and logistical challenges, to the extent possible.Continue Reading The Potential Impact of Remote Working on Your Business

The rapid spread of the coronavirus is causing alarm around the world.  This almost unprecedented global event is leading to various unforeseen consequences, including the collection, use and sharing of personal data of affected individuals – and, in some cases, persons connected to them – in ways not envisaged only a few weeks ago.  The processing of personal data of this nature can potentially have serious, albeit sometimes unintended, consequences.
Continue Reading Thoughts on the Use of Personal Data in the Fight Against Coronavirus

The Opinion of Advocate-General (AG) Henrik Saugmandsgaardøe in the “Schrems II” case (C-311-18) was delivered on 19 December and will likely leave organisations, which currently rely on EC Commission-approved standard contractual clauses to ensure adequate protection for personal data that they transfer internationally heaving a collective sigh of relief, at least for the moment.
Continue Reading Schrems II and Standard Contractual Clauses – the Advocate-General’s Opinion