Showing archive for: “GDPR”
Should the GDPR Prohibit AI?
The European Data Protection Board’s (EDPB) Nov. 5 stakeholder consultation on AI models and data protection—organized to gather input for an upcoming Irish Data Protection Commission opinion under Article 64(2) of the General Data Protection Regulation (GDPR)—showcased significant lingering disagreement on how the GDPR should apply to AI. While the event was not intended to ... Should the GDPR Prohibit AI?
The Cookie Plan Crumbles: Stuck in the Middle with Google
Google recently announced that it has changed its plans to phase out third-party cookies in the Chrome web browser. The company had previously planned to disable third-party cookies in Chrome, a change supported by many in the privacy-stakeholder community, but which was met with criticism from the adtech industry and competition lawyers. Google’s new plans ... The Cookie Plan Crumbles: Stuck in the Middle with Google
Google Previews the Coming Tussle Between GDPR and DMA Article 6(11)
Among the less-discussed requirements of the European Union’s Digital Markets Act (DMA) is the data-sharing obligation created by Article 6(11). This provision requires firms designated under the law as “gatekeepers” to share “ranking, query, click and view data” with third-party online search engines, while ensuring that any personal data is anonymized. Given how restrictively the ... Google Previews the Coming Tussle Between GDPR and DMA Article 6(11)
Confronting the DMA’s Shaky Suppositions
It’s easy for politicians to make unrealistic promises. Indeed, without a healthy skepticism on the part of the public, they can grow like weeds. In the world of digital policy, the European Union’s Digital Markets Act (DMA) has proven fertile ground for just such promises. We’ve been told that large digital platforms are the source ... Confronting the DMA’s Shaky Suppositions
Does the DMA Let Gatekeepers Protect Data Privacy and Security?
It’s been an eventful two weeks for those following the story of the European Union’s implementation of the Digital Markets Act. On April 18, the European Commission began a series of workshops with the companies designated as “gatekeepers” under the DMA: Apple, Meta, Alphabet, Amazon, ByteDance, and Microsoft. And even as those workshops were still ... Does the DMA Let Gatekeepers Protect Data Privacy and Security?
From Europe, with Love: Lessons in Regulatory Humility Following the DMA Implementation
The European Union’s implementation of the Digital Markets Act (DMA), whose stated goal is to bring more “fairness” and “contestability” to digital markets, could offer some important regulatory lessons to those countries around the world that have been rushing to emulate the Old Continent. The first regards “regulatory humility.” Designing ex ante regulation to promote ... From Europe, with Love: Lessons in Regulatory Humility Following the DMA Implementation
Will the EU-U.S. Data Privacy Bridge Hold?
With the European Commission’s recent announcement that it had deemed the revamped data-protection framework from the United States to be “adequate” under the European Union’s stringent General Data Protection Regulation (GDPR), the stage is set for what promises to be a legal rollercoaster in the European Court of Justice (CJEU). The Commission’s decision is certain ... Will the EU-U.S. Data Privacy Bridge Hold?
Norwegian Decision Banning Behavioral Advertising on Facebook and Instagram
The Norwegian Data Protection Authority (DPA) on July 14 imposed a temporary three-month ban on “behavioural advertising” on Facebook and Instagram to users based in Norway. The decision relied on the “urgency procedure” under the General Data Protection Regulation (GDPR), which exceptionally allows direct regulatory interventions by other national authorities than the authority of the country ... Norwegian Decision Banning Behavioral Advertising on Facebook and Instagram
The CJEU’s Decision in Meta’s Competition Case: Sensitive Data and Privacy Enforcement by Competition Authorities (Part 2)
Yesterday, I delved into the recent judgment in the Meta case (Case C-252/21) from the Court of Justice of the European Union (CJEU). I gave a preliminary analysis of the court’s view on some of the complexities surrounding the processing of personal data for personalized advertising under the GDPR, focusing on three lawful bases for ... The CJEU’s Decision in Meta’s Competition Case: Sensitive Data and Privacy Enforcement by Competition Authorities (Part 2)
The CJEU’s Decision in Meta’s Competition Case: Consequences for Personalized Advertising Under the GDPR (Part 1)
Today’s judgment from the Court of Justice of the European Union (CJEU) in Meta’s case (Case C-252/21) offers new insights into the complexities surrounding personalized advertising under the EU General Data Protection Regulation (GDPR). In the decision, in which the CJEU gave the green light to an attempt by the German competition authority (FCO) to ... The CJEU’s Decision in Meta’s Competition Case: Consequences for Personalized Advertising Under the GDPR (Part 1)
Biweekly FTC Roundup: Bureau of Let’s-Sue-Meta Edition
The Federal Trade Commission (FTC) might soon be charging rent to Meta Inc. The commission earlier this week issued (bear with me) an “Order to Show Cause why the Commission should not modify its Decision and Order, In the Matter of Facebook, Inc., Docket No. C-4365 (July 27, 2012), as modified by Order Modifying Prior Decision and Order, In ... Biweekly FTC Roundup: Bureau of Let’s-Sue-Meta Edition
The AI Act and Regulatory Overaggregation
It appears that the emergence of ChatGPT and other artificial-intelligence systems has complicated the European Union’s efforts to implement its AI Act, mostly by challenging its underlying assumptions. The proposed regulation seeks to govern a diverse and rapidly growing AI landscape. In reality, however, there is no single thing that can be called “AI.” Instead, the category comprises ... The AI Act and Regulatory Overaggregation