<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>GDPR on Digitaliziran si</title><link>https://digitaliziran.si/categories/gdpr/</link><description>Recent content in GDPR on Digitaliziran si</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 02 Dec 2025 17:11:12 +0000</lastBuildDate><atom:link href="https://digitaliziran.si/categories/gdpr/index.xml" rel="self" type="application/rss+xml"/><item><title>EU Court Ruling Forces Marketplaces to Verify User Data Before Publishing: Is Your Platform Compliant?</title><link>https://digitaliziran.si/2025/12/02/eu-court-ruling-forces-marketplaces-to-verify-user-data-before-publishing-is-your-platform-compliant/</link><pubDate>Tue, 02 Dec 2025 17:11:12 +0000</pubDate><guid>https://digitaliziran.si/2025/12/02/eu-court-ruling-forces-marketplaces-to-verify-user-data-before-publishing-is-your-platform-compliant/</guid><description>&lt;p&gt;Does your online marketplace publish user-generated listings without verifying the personal data they contain? A &lt;a href="https://curia.europa.eu/juris/document/document.jsf;jsessionid=E541D6943FA2B3D1E87A0FCA78DCF7D7?text=&amp;amp;docid=306764&amp;amp;pageIndex=0&amp;amp;doclang=EN&amp;amp;mode=req&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;cid=15422674"&gt;landmark ruling from the Court of Justice of the European Union&lt;/a&gt; in &lt;em&gt;Russmedia Digital&lt;/em&gt; (C-492/23) just fundamentally changed how platforms must handle &lt;a href="https://gdpr-info.eu/issues/personal-data/"&gt;personal data&lt;/a&gt; - and the compliance burden is substantial.&lt;/p&gt;
&lt;h2 id="marketplaces-are-now-data-controllers"&gt;Marketplaces Are Now Data Controllers&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://europa.eu/european-union/about-eu/institutions-bodies/court-justice_en"&gt;Court&lt;/a&gt; ruled that marketplace operators qualify as &lt;a href="https://gdpr-info.eu/art-4-gdpr/"&gt;data controllers&lt;/a&gt; under the &lt;a href="https://gdpr-info.eu/"&gt;General Data Protection Regulation (GDPR)&lt;/a&gt; for personal data contained in user-posted listings - even when platforms neither create the content nor know the advertiser&amp;rsquo;s identity. The rationale? By deciding to make listings public and exploiting them commercially, platforms exercise control over personal data processing.&lt;/p&gt;</description></item><item><title>EU Digital Omnibus Drops: Is Your Compliance Strategy About to Become Obsolete?</title><link>https://digitaliziran.si/2025/11/25/eu-digital-omnibus-drops-is-your-compliance-strategy-about-to-become-obsolete/</link><pubDate>Tue, 25 Nov 2025 12:30:55 +0000</pubDate><guid>https://digitaliziran.si/2025/11/25/eu-digital-omnibus-drops-is-your-compliance-strategy-about-to-become-obsolete/</guid><description>&lt;p&gt;Are you still building your compliance framework around the current GDPR, AI Act, and Data Act requirements? The European Commission just published the most sweeping reform of EU digital laws since 2018 - and everything you thought you knew about data protection compliance might be about to change.&lt;/p&gt;
&lt;h2 id="the-regulatory-earthquake-you-cant-ignore"&gt;The Regulatory Earthquake You Can&amp;rsquo;t Ignore&lt;/h2&gt;
&lt;p&gt;On 19 November 2025, the European Commission released two proposed regulations that will fundamentally reshape how businesses handle data, AI, and cybersecurity in Europe. The Digital Omnibus (2025/0360) and Digital Omnibus on AI (2025/0359) aren&amp;rsquo;t minor tweaks - they&amp;rsquo;re a complete rethinking of the EU&amp;rsquo;s approach to digital regulation.&lt;/p&gt;</description></item><item><title>Hamburg's €492,000 Fine Signals New Era of AI Transparency Enforcement: Are You Ready?</title><link>https://digitaliziran.si/2025/10/09/hamburgs-e492000-fine-signals-new-era-of-ai-transparency-enforcement-are-you-ready/</link><pubDate>Thu, 09 Oct 2025 08:15:00 +0000</pubDate><guid>https://digitaliziran.si/2025/10/09/hamburgs-e492000-fine-signals-new-era-of-ai-transparency-enforcement-are-you-ready/</guid><description>&lt;p&gt;Is your organization using &lt;a href="https://gdpr-info.eu/art-22-gdpr/"&gt;automated decision-making systems&lt;/a&gt; without fully understanding the transparency requirements? The &lt;a href="https://www.clydeco.com/en/insights/2025/10/lessons-from-hamburg-commissioner-for-data-protect"&gt;Hamburg Commissioner for Data Protection&amp;rsquo;s recent €492,000 fine&lt;/a&gt; against a financial services provider should serve as your wake-up call.&lt;/p&gt;
&lt;h2 id="the-case-that-changes-everything"&gt;The Case That Changes Everything&lt;/h2&gt;
&lt;p&gt;The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed this substantial penalty on a financial company for failing to provide adequate transparency in automated credit card application decisions. The violation? The company couldn&amp;rsquo;t explain to customers why their applications were rejected by their &lt;a href="https://en.wikipedia.org/wiki/Algorithmic_transparency"&gt;algorithmic systems&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>CJEU Ruling Redefines Personal Data: Is Your Pseudonymisation Strategy Still Compliant?</title><link>https://digitaliziran.si/2025/09/24/cjeu-ruling-redefines-personal-data-is-your-pseudonymisation-strategy-still-compliant/</link><pubDate>Wed, 24 Sep 2025 10:25:00 +0000</pubDate><guid>https://digitaliziran.si/2025/09/24/cjeu-ruling-redefines-personal-data-is-your-pseudonymisation-strategy-still-compliant/</guid><description>&lt;p&gt;Are you certain your pseudonymised data transfers comply with &lt;a href="https://gdpr-info.eu/"&gt;GDPR&lt;/a&gt;? A significant ruling from the Court of Justice of the European Union (CJEU) on September 4, 2025, has provided important clarification on when pseudonymised data qualifies as &lt;a href="https://gdpr-info.eu/issues/personal-data/"&gt;personal data&lt;/a&gt; - and the implications could refine your data management strategy.&lt;/p&gt;
&lt;h2 id="the-ruling-that-provides-clarity"&gt;The Ruling That Provides Clarity&lt;/h2&gt;
&lt;p&gt;In the case of &lt;a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;amp;docid=295078&amp;amp;pageIndex=0&amp;amp;doclang=EN"&gt;European Data Protection Supervisor (EDPS) v Single Resolution Board (SRB)&lt;/a&gt; (C-413/23), the CJEU confirmed that &lt;strong&gt;personal data is a relative concept&lt;/strong&gt;. This means data can be pseudonymous in one party&amp;rsquo;s hands while being effectively anonymous for another recipient.&lt;/p&gt;</description></item><item><title>EU Court Ruling Redefines Pseudonymized Data: Is Your Company's Privacy Strategy Still Valid?</title><link>https://digitaliziran.si/2025/09/08/eu-court-ruling-redefines-pseudonymized-data-is-your-companys-privacy-strategy-still-valid/</link><pubDate>Mon, 08 Sep 2025 07:05:25 +0000</pubDate><guid>https://digitaliziran.si/2025/09/08/eu-court-ruling-redefines-pseudonymized-data-is-your-companys-privacy-strategy-still-valid/</guid><description>&lt;p&gt;Are you confident that your &lt;a href="https://dataprivacymanager.net/pseudonymization-according-to-the-gdpr/"&gt;pseudonymized data&lt;/a&gt; transfers comply with &lt;a href="https://gdpr.eu/"&gt;GDPR&lt;/a&gt;? A significant ruling from the Court of Justice of the European Union (CJEU) on September 4, 2025, has provided welcome clarity for how organizations handle supposedly &amp;ldquo;anonymized&amp;rdquo; information.&lt;/p&gt;
&lt;h2 id="the-ruling-that-clarifies-data-privacy"&gt;The Ruling That Clarifies Data Privacy&lt;/h2&gt;
&lt;p&gt;The &lt;a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;amp;docid=303863&amp;amp;pageIndex=0&amp;amp;doclang=EN&amp;amp;mode=lst&amp;amp;dir=&amp;amp;occ=first&amp;amp;part=1&amp;amp;cid=16531016"&gt;CJEU&amp;rsquo;s latest decision&lt;/a&gt; in the case of &lt;a href="https://edps.europa.eu/"&gt;European Data Protection Supervisor (EDPS)&lt;/a&gt; v &lt;a href="https://www.srb.europa.eu/"&gt;Single Resolution Board (SRB)&lt;/a&gt; (C-413/23 P) addresses a critical question that has puzzled data protection officers for years: when does &lt;a href="https://www.edpb.europa.eu/sme-data-protection-guide/faq-frequently-asked-questions/answer/what-difference-between_en"&gt;pseudonymized data&lt;/a&gt; still count as personal data under GDPR?&lt;/p&gt;</description></item><item><title>Microsoft Admits It Cannot Guarantee EU Data Sovereignty: Is Your Organization at Risk?</title><link>https://digitaliziran.si/2025/07/30/microsoft-admits-it-cannot-guarantee-eu-data-sovereignty-is-your-organization-at-risk/</link><pubDate>Wed, 30 Jul 2025 14:34:11 +0000</pubDate><guid>https://digitaliziran.si/2025/07/30/microsoft-admits-it-cannot-guarantee-eu-data-sovereignty-is-your-organization-at-risk/</guid><description>&lt;p&gt;&lt;strong&gt;Are you confident your European data is truly protected from foreign surveillance?&lt;/strong&gt; Microsoft&amp;rsquo;s recent admission under oath has raised important questions about data sovereignty, but the full picture is more nuanced than initial headlines suggest.&lt;/p&gt;
&lt;h2 id="the-uncomfortable-truth---and-microsofts-response"&gt;The Uncomfortable Truth - And Microsoft&amp;rsquo;s Response&lt;/h2&gt;
&lt;p&gt;Microsoft has publicly acknowledged that it &lt;a href="https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/"&gt;cannot guarantee data sovereignty&lt;/a&gt; for customers in France and, by extension, the wider European Union. This admission came during legal proceedings where Microsoft France&amp;rsquo;s General Counsel, Anton Carniaux, confirmed the company&amp;rsquo;s inability to resist US government data requests under the &lt;a href="https://www.justice.gov/criminal/cloud-act-resources"&gt;US CLOUD Act&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Your Work Emails Are Personal Data: The GDPR Ruling That Changes Everything</title><link>https://digitaliziran.si/2025/06/26/your-work-emails-are-personal-data-the-gdpr-ruling-that-changes-everything/</link><pubDate>Thu, 26 Jun 2025 14:36:00 +0000</pubDate><guid>https://digitaliziran.si/2025/06/26/your-work-emails-are-personal-data-the-gdpr-ruling-that-changes-everything/</guid><description>&lt;p&gt;Do you think your professional emails belong to your employer? Think again. A recent legal clarification has confirmed that &lt;strong&gt;professional emails can contain personal data under the &lt;a href="https://gdpr-info.eu/"&gt;General Data Protection Regulation (GDPR)&lt;/a&gt;&lt;/strong&gt; - but the reality is more nuanced than many headlines suggest, and this ruling could fundamentally change how your workplace handles your communications.&lt;/p&gt;
&lt;h2 id="the-ruling-that-matters---with-important-caveats"&gt;The Ruling That Matters - With Important Caveats&lt;/h2&gt;
&lt;p&gt;According to &lt;a href="https://www.applebyglobal.com/publications/professional-emails-are-personal-data/"&gt;Appleby Global&amp;rsquo;s recent analysis&lt;/a&gt;, professional emails can fall under GDPR protection as &lt;a href="https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/personal-information-what-is-it/what-is-personal-data/what-is-personal-data/"&gt;personal data&lt;/a&gt;. However, &lt;strong&gt;it&amp;rsquo;s crucial to understand that not all professional emails automatically qualify as personal data&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>EDPB Guidelines Expose Blockchain's GDPR Nightmare: Is BitTorrent the Unexpected Solution?</title><link>https://digitaliziran.si/2025/06/24/edpb-guidelines-expose-blockchains-gdpr-nightmare-is-bittorrent-the-unexpected-solution/</link><pubDate>Tue, 24 Jun 2025 08:32:04 +0000</pubDate><guid>https://digitaliziran.si/2025/06/24/edpb-guidelines-expose-blockchains-gdpr-nightmare-is-bittorrent-the-unexpected-solution/</guid><description>&lt;p&gt;Are you building on &lt;a href="https://www.investopedia.com/terms/b/blockchain.asp"&gt;blockchain technology&lt;/a&gt; without considering the privacy compliance minefield you&amp;rsquo;re walking into? The &lt;a href="https://edpb.europa.eu/"&gt;European Data Protection Board&amp;rsquo;s (EDPB)&lt;/a&gt; latest guidelines reveal a fundamental incompatibility between blockchain&amp;rsquo;s core features and &lt;a href="https://gdpr.eu/what-is-gdpr/"&gt;GDPR&lt;/a&gt; requirements that could derail your digital transformation plans.&lt;/p&gt;
&lt;h2 id="the-immutability-problem"&gt;The Immutability Problem&lt;/h2&gt;
&lt;p&gt;Blockchain&amp;rsquo;s greatest strength - its &lt;a href="https://www.ibm.com/topics/immutable-ledger"&gt;immutable ledger&lt;/a&gt; - has become its GDPR Achilles&amp;rsquo; heel. &lt;a href="https://www.williamfry.com/knowledge/edpb-guidelines-raise-questions-on-how-gdpr-interacts-with-blockchain/"&gt;According to new EDPB guidelines&lt;/a&gt;, the technology&amp;rsquo;s inability to modify or delete records directly conflicts with data subjects&amp;rsquo; rights to erasure and rectification under &lt;a href="https://gdpr-info.eu/art-17-gdpr/"&gt;GDPR Articles 17&lt;/a&gt; and &lt;a href="https://gdpr-info.eu/art-16-gdpr/"&gt;16&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Are You Unknowingly Using What Congress Might Soon Classify as the "Dark Web"?</title><link>https://digitaliziran.si/2025/06/12/are-you-unknowingly-using-what-congress-might-soon-classify-as-the-dark-web/</link><pubDate>Thu, 12 Jun 2025 15:56:48 +0000</pubDate><guid>https://digitaliziran.si/2025/06/12/are-you-unknowingly-using-what-congress-might-soon-classify-as-the-dark-web/</guid><description>&lt;p&gt;Are you unknowingly using what Congress might soon classify as the &amp;ldquo;&lt;a href="https://en.wikipedia.org/wiki/Dark_web"&gt;dark web&lt;/a&gt;&amp;rdquo;? A new Senate bill targeting &lt;a href="https://www.cdc.gov/opioids/basics/index.html"&gt;opioid&lt;/a&gt; trafficking contains a definition so broad it could sweep up everything from your private &lt;a href="https://www.whatsapp.com/"&gt;WhatsApp&lt;/a&gt; conversations to your company&amp;rsquo;s &lt;a href="https://www.kaspersky.com/resource-center/definitions/what-is-a-vpn"&gt;VPN&lt;/a&gt; access.&lt;/p&gt;
&lt;h2 id="the-definitional-disaster"&gt;The Definitional Disaster&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.congress.gov/bill/119th-congress/senate-bill/1975/text/is"&gt;Senate Bill 1975&lt;/a&gt;, the Dark Web Interdiction Act of 2025, aims to prohibit opioid delivery through dark web channels. While the intent is commendable, the &lt;a href="https://www.congress.gov/bill/119th-congress/senate-bill/1975/text/is#:~:text=DEFINITION%20OF%20DARK%20WEB"&gt;bill&amp;rsquo;s definition of &amp;ldquo;dark web&amp;rdquo;&lt;/a&gt; is alarmingly overbroad, requiring only that content be (A) not indexed by search engines AND (B) require specific software or configurations that conceal user identities.&lt;/p&gt;</description></item><item><title>Localhost tracking</title><link>https://digitaliziran.si/2025/06/12/localhost-tracking/</link><pubDate>Thu, 12 Jun 2025 10:38:00 +0000</pubDate><guid>https://digitaliziran.si/2025/06/12/localhost-tracking/</guid><description>&lt;p&gt;&lt;strong&gt;Are your privacy tools actually protecting you? A shocking new investigation reveals that Meta has been using a sophisticated &amp;ldquo;localhost tracking&amp;rdquo; technique that can link your web browsing to your real identity - even when you&amp;rsquo;re using VPNs, incognito mode, or have deleted all your cookies.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="the-hidden-tracking-method"&gt;The Hidden Tracking Method&lt;/h2&gt;
&lt;p&gt;Researchers discovered that Meta&amp;rsquo;s Facebook and Instagram apps have been secretly communicating with web browsers through hidden &lt;a href="https://phoenixnap.com/kb/127-0-0-1-localhost"&gt;localhost&lt;/a&gt; connections since September 2024. This technique allows Meta to bypass &lt;a href="https://www.android.com/"&gt;Android&amp;rsquo;s&lt;/a&gt; built-in security protections and create detailed profiles of your online activity without your knowledge or consent.&lt;/p&gt;</description></item></channel></rss>