DSGVO Archives - m&k https://www.markt-kom.com/en/tag/dsgvo/ The creative side of the economy Tue, Jul 23, 2024 12:26:31 +0000 en-US hourly 1 https://wordpress.org/?v=7.1.2 https://www.markt-kom.com/wp-content/uploads/2024/07/favicon-150x150.png DSGVO Archives - m&k https://www.markt-kom.com/en/tag/dsgvo/ 32 32 Web-Tracking und Risikomanagement https://www.markt-kom.com/en/digital/web-tracking-und-risikomanagement/ Wed, June 14, 2023, 11:21:39 PM +0000 https://www.markt-kom.com/?p=198902 A functioning risk management is a control instrument for achieving the company's goals. For larger companies it is mandatory, for others it makes sense: to identify, analyze, treat and monitor risks. These risks are not limited to financial, strategic or information security risks. Data protection, i.e., the protection of the individual from infringing data processing, also harbors risks.

Privacy risks in tracking

If "cookies" are placed on an end device during web tracking, the user is generally considered to be an identifiable person via IP address and, as a result, Swiss data protection law is applicable. A Swiss website operator is quickly also subject to EU data protection law if he tracks his EU traffic or selectively plays out offers in this area. The data protection law requirements are manifold: information obligations, data subject rights, data inventory, data security or the cookie consent question (EU yes, CH no) and much more. Data protection law requires regular risk analyses here, whereby assessing data protection risks is not easy even for specialists.

One bugbear is big-tech data transfers abroad and potential access by authorities. Although the probability is considered low, there would be a cluster risk associated with this: Requests for information, FDPIC notification, lawsuits, loss of reputation, very high threat of fines (EU) and newly personal fines in Switzerland. Even standard data protection clauses do not offer sacrosanct protection, as the record fine from Ireland shows. Another risk is the assurance of anonymization of IP addresses in data protection declarations, because this is relative, as it only takes place after transmission to the data center.

How are data protection risks handled?

The seemingly cheapest and simplest treatment is to accept a risk, which must be formally documented with reasons (lack of resources). Risks are transferred classically via insurance. Cyber and D&O insurances, however, refuse to cover personal fine risks.

The right way is to reduce. This respects the risk-based approach of data protection law, according to which protective measures are taken in function of the probability of infringement and possible effects. The focus here is on the use of a European tracking solution. In addition to sharpened privacy awareness and on-site data centers, such solutions are equipped with first-class features. Data proximity and data sovereignty are particularly valued by companies from sensitive and regulated industries. Next, avoidance is an option by relying on tracking technology that does not require cookies and still provides useful marketing data. Companies that systematically address tracking risks often choose a mix: cookie tracking where consent is available or not necessary, and cookieless tracking where it is not.


Author: Thomas Michel, Information Security Officer at Capture Media.

More information is available here.

]]>
Soziale Medien: EU verhängt Rekordstrafe gegen Facebook-Konzern Meta https://www.markt-kom.com/en/digital/social-media/soziale-medien-eu-verhaengt-rekordstrafe-gegen-facebook-konzern-meta/ Mon, May 22, 2023 10:59:47 +0000 https://www.markt-kom.com/?p=197892
Dima Solomin / Unsplash

The case is about Facebook's involvement in mass surveillance by Anglo-American intelligence agencies, which was revealed ten years ago by U.S. whistleblower Edward Snowden. Austrian privacy activist Max Schrems brought a complaint against Facebook at the time.

The fine imposed by the DPC dwarfs Amazon.com's previous record fine of €746 million in Luxembourg. In addition, Meta must stop any further transfer of European personal data to the United States, as the company remains subject to U.S. surveillance laws.

Is Meta fighting back?

Meta did not comment on the record fine for the time being. However, experts assume that the U.S. company will appeal the decision. The court proceedings, however, could stretch on for years. In the meantime, a new data pact between the European Union and the U.S. could come into force, which will re-regulate transatlantic data traffic.

Meta had previously threatened several times to withdraw completely from the EU if transatlantic data transfer was not possible on a permanent basis. Schrems explained that the fine imposed could have been much higher: "The maximum fine is over four billion. And Meta knowingly violated the GDPR for ten years to make a profit." If U.S. surveillance laws are not changed, Meta will now likely have to fundamentally restructure its systems, Schrems explained.

Years of struggle

For years, the Irish data protection authority DPC had refused to take action against Facebook in this matter. Ultimately, the European Data Protection Committee (EDSA) obliged the DPC to impose a penalty on the social network. The current decision only applies to Facebook, not to other services from the meta group such as Instagram or WhatsApp.

However, Meta had already been fined 390 million euros by the DPC in January for forcing Facebook and Instagram users to agree to personalized advertising.

So far, the new penalty for Meta has seen fines totaling four billion euros since the General Data Protection Regulation came into force five years ago. Meta now features six times in the list of the ten highest fines, with penalties now totaling 2.5 billion euros. (SDA)

]]>
Datenschutz: Neues Whitepaper zum nDSG https://www.markt-kom.com/en/markom/datenschutz-neues-whitepaper-zum-ndsg/ Tue, Feb 14, 2023 09:05:15 +0000 https://www.markt-kom.com/?p=193422
Image: Campaign Creators/ Unsplash

The new Data Protection Act DSG (nDSG) comes into force on September 1, 2023, more than five years after its European counterpart, the General Data Protection Regulation DSGVO. This new regulation brings challenges and opportunities for Swiss companies: While marketing and sales come first and juggle the largest amounts of personal data of prospects and customers, HR departments with their employee data are also affected.

Aside from compliance, data is both a big challenge and an opportunity for companies to differentiate themselves from the competition. It enables them to develop new use cases and be more agile in managing activities and performance. If companies master the entire chain from collection to use of data, they have the opportunity to create value here.

If you don't address the issue of data privacy properly, you risk your reputation. This is because the likelihood of complaints and sanctions going public is high and can seriously damage the company's image. The five-year history of the GDPR has shown a significant increase in complaints and sanctions as consumers have become aware of the challenges associated with the use of their personal data.

New whitepaper

The most important points that Swiss companies need to consider in order to turn data into a competitive advantage rather than a risk have been summarized by Colombus Consulting in collaboration with Brandit in a new whitepaper.

Download.

]]>
Data Privacy: So vereinbart man die Marketingstrategie mit den gesetzlichen Vorschriften https://www.markt-kom.com/en/digital/data-privacy-so-stimmt-die-marketingstrategie-mit-den-gesetzlichen-vorschriften-ueberein/ Mon, 16 Jan 2023 13:18:33 +0000 https://www.markt-kom.com/?p=192330 Consumers are now more aware than ever of the value their data represents to businesses and how companies can use it. In this context, a number of data protection regulations have been enacted around the world. Their goal? To ensure that every user has the right to protect and access their personal data. This can be a tricky issue for marketers, and even more so for those dealing with different types of data in different countries.

What is Data Privacy?

The term data protection refers to the rules that apply to the use of users' personal data in the course of a professional activity. Each country has its own regulations, so it can be difficult for companies to comply with them. However, all these regulations have the same basis, namely:

- Consent: Users must be informed in clear form about how their data may be collected, stored and used. They must give their express consent to the collection, storage and use of this data.

- Legal conditions: The regulations define the consequences and legal obligations for companies that collect and use this type of data.

- Rights of users: Users have access to their personal data at any time and may request its modification, correction, deletion or restoration.

- Data security: Every company must inform the authorities as soon as possible if it has been identified as having suffered a personal data breach.

What kind of data are we talking about?

Any type of personal data is subject to data protection regulations. Thus, any data that allows a person to be identified, directly or indirectly, falls within this legal framework. These personal data are:

- Name, first name, e-mail address and phone number
- Any kind of socio-demographic data (profession, gender, age...)
- Any kind of geolocation
- Data related to the way a user uses the Internet (IP address, behavioral data...).

It should be noted that data that has been passed on at the initiative of the user is also affected. The same applies to internal company data (all data relating to the company's employees).

Who is affected by data protection?

Any company that collects, stores or uses personal data about its users is affected by data protection. Most regulations are designed from the user's perspective. This means that they apply to companies that use personal data of users located in the region to which these regulations apply. In other words, even if a company is not located in a region where a particular regulation applies, or its data is stored in another country, it is
the company is nevertheless affected, its users should be located in this region. Therefore, it is important to know the various regulations and comply with them.

What regulations are in place to monitor data protection?

The following explains the various personal data protection regulations that should be known in order to best adapt marketing activities to the regulations.

The DSGVO/GDPR (General Data Protection Regulation) applies in Europe. This is a regulation of the European Union that came into force in 2018 and is enforced by the respective competent national authorities.
It requires that companies, among other things,...
- require users to ask for their explicit consent when collecting their personal data
- have a register explaining how this data is collected, stored and protected at all times
- allow users to modify, correct, delete or retrieve their personal data.

In California, it is the CCPA (California Consumer Privacy Act) that must be complied with. This regulation, which went into effect in 2020, is very similar to the GDPR, but specifically regulates how companies store and share the data of California residents. These users must be informed about how their data is being collected, and they must have access to that data at any time to request its deletion.

In Brazil, the LGPD (Lei Geral de Proteção de Dados), which came into force in August 2020, regulates the concept of data protection. This law, which is also directly based on the GDPR, defines how companies collect, process and share the personal data of users residing in Brazil.

The rules on data transfer outside the EU

If a company needs to transfer data to countries outside the EU, it is necessary to comply with the regulations in force in the countries. In France, for example, the CNIL (Commission Nationale de l'Informatique et des Libertés), in Germany the BFDI (Bundesbeauftragter für den Datenschutz und die Informationsfreiheit) and in the UK the ICO (Information Commissioner's Office) no longer have to grant approval for data transfers outside the EU since the GDPR came into force if they are based on ...
- Standard Contractual Clauses ("SCC") established by the European Commission,
- a code of conduct approved by the EU,
- an internal regulation approved by the EU for a specific company or
- be based on a certification approved by the EU.

It is important to note, however, that both the company exporting personal data and the company importing it must check exactly what the specific regulations of the country in question are.

What changes are on the horizon? And how will they affect the market?

As the concept of data protection is constantly the subject of new laws and regulations, it is crucial to anticipate upcoming changes in this area.

revDSG: a new law for data protection in Switzerland

In Switzerland, companies must comply with the new data protection law revDSG from September 1, 2023. This law is also aligned with the GDPR to maintain the free flow of data between Switzerland and the EU and to ensure the protection of users' rights.

- It contains the main principles of the GDPR
- Users must be informed about the collection of their personal data (not only about sensitive data, as already mentioned in the law)
- Companies must create a data register
- In addition, they must inform the data protection officer immediately if a security breach is detected
- The principles of privacy by design and privacy by default are introduced by the law.

Data transfer between the USA and the EU

In early October 2022, the U.S. President announced that a new regulation for data transfers between the United States and the European Union will be introduced to ensure that this data is as well protected as under the GDPR. This new regulation replaces the two previous draft frameworks "Safe Harbor" and "Privacy Shield", which were declared invalid by the European judiciary.

This regulation...
- Establishes a new privacy review court under the authority of the U.S. Department of Justice
- provides that the United States shall limit access by its competent authorities to the data of Europeans to what is "necessary" and "proportionate."

Navigating the numerous privacy regulations in place around the world can be challenging for marketers, who must ensure compliance while delivering a good user experience and optimizing campaign performance.
To achieve this balance, a powerful Consent Management Platform (CMP) is essential, as well as advanced tracking across all platforms and monitoring of results through analytics.


* Zbynek Zapletal is Director of Programmatic & Tech Development DACH & CZ at Gamned Suisse SA.

]]>
Meta darf personenbezogene Daten nicht für Werbung benutzen https://www.markt-kom.com/en/digital/meta-darf-personenbezogene-daten-nicht-fuer-werbung-benutzen/ Thu, Jan 5, 2023 11:14:43 +0000 https://www.markt-kom.com/?p=191874
Image: unsplash.com / Dima Solomin

At the same time, it imposed a fine of 390 million euros. The DPC announced that the group had violated the EU's General Data Protection Regulation with its Facebook and Instagram platforms.

Both cases are about personalized advertising and the way Meta collects and processes users' personal data. Facebook will be fined 210 million euros for the infringement, and Instagram 180 million euros.

Demand from EU authority

The Irish regulator had long been reluctant to take action against Facebook or Meta following complaints from Facebook customers and privacy activists. In December, the European Data Protection Board overruled the DPC and called on the Irish authority to take decisive action against the Internet giant.

Since 2018, the General Data Protection Regulation (GDPR) has regulated the conditions under which personal data may be used. In some cases, this can be done without the explicit consent of the customer, for example when an online store transfers data to the parcel service provider.

Interpretation not accepted

After the entry into force of the GDPR in 2018, Facebook (now Meta Platforms) had declared in its terms of use the playing of personally tailored advertising as part of the service, for which no separate consent was required. This interpretation has now been overturned.

The authority concluded that the company then in a sense pressured its users to accept certain conditions, as otherwise the services would no longer have been usable for them. In a first reaction, Facebook stated: "We strongly believe that our approach respects the GDPR and are therefore disappointed by these decisions."

The Irish authority is also requiring Meta to change its data processing practices within three months.

Data protection activist Max Schrems, who is one of the complainants, criticized Meta's approach, saying, "Instead of having a yes/no option for personalized advertising, they simply moved the consent clause to the terms and conditions. That's not only unfair, it's clearly illegal."

]]>