Posts

EDPB provides input on biometric use in airports

 The French Supervisory Authority has sought the European Data Protection Board's opinion on the use of facial recognition technology by airport operators and airline companies for biometric authentication of passengers, with the objective of enhancing passenger flow at airports. The Board underscores that the use of biometric data, particularly facial recognition technology, poses significant risks to the rights and freedoms of individuals. This data type is given special protection under Article 9 of the GDPR. Prior to implementing such technologies, controllers are strongly advised to thoroughly evaluate the impact on individuals' fundamental rights and freedoms, and to consider if less invasive methods can achieve the intended purpose. The focus of this opinion is on the compatibility of the processing with specific articles of the GDPR, with the aim of streamlining passenger flow at airports at security checkpoints, baggage drop-off, boarding, and access to passenger loung...

Revised OECD AI Principles Address Emerging Challenges

The OECD (Organization for Economic Cooperation and Development) recently updated its AI Principles to address the rapid development of AI, particularly general-purpose and generative AI. These updated principles ensure AI is used responsibly and ethically while promoting innovation and economic growth. Here's a summary of the key points : Focus on emerging challenges:  The revisions address privacy, intellectual property, safety, and information integrity in the context of new AI advancements. Global impact:   With 47 members, including the EU, the OECD AI Principles serve as a blueprint for international AI policy frameworks. The updated AI Principles: It strike a delicate balance between fostering innovation and  upholding  ethical standards, advocating  for  trustworthy AI that respects human rights and democratic values. Rapid AI development:  The OECD reports significant growth in AI investment, skills demand, and adoption by large firms. T...

Handling Data Breaches Under EU GDPR: A Step-by-Step Guide

Data breaches are an unfortunate reality in today's digital landscape. When a breach involves the personal data of EU residents, the EU's General Data Protection Regulation (GDPR) comes into play. This means strict reporting timelines, potential fines, and reputational harm. Let's break down how to respond effectively to a personal data breach within the GDPR framework. Key Roles and Responsibilities Security Incident Team: Reports the suspected breach immediately to the Data Protection Officer (DPO). Data Protection Officer (DPO): Assesses the risk to individuals' rights and freedoms. Notifies the Data Protection Authority (DPA) and, if necessary, the affected individuals. Collaborates with the organization's public relations team for communication. Processor's DPO: Notifies the controller of the breach as per the terms of their contract. Action Plan for Data Breach Response Inform the DPO: Immediate notification is crucial upon discovery of a bre...