DATA PROTECTION UPDATES

LEGAL UPDATES ON DATA PROTECTION AND PRIVACY 

You may follow the recent developments on Data Protection and Privacy in Türkiye and around the World. 

ICO FINES DIFFERENT COMPANIES A TOTAL OF £590,000:

The ICO has fined 5 different companies a total of £590,000 for making 1.9 million marketing calls to elderly and vulnerable people.

This decision is aimed at preventing marketing calls, which are usually made to elderly and vulnerable people in order to reach them and insure their various household goods. Andy Curry, the ICO's Investigations Manager, said: "We are working to protect these people who are seen as easy prey.

22.09.2023

ADMINISTRATIVE FINE AGAINST TIKOK BY THE IRISH DATA PROTECTION AUTHORITY DPC:

The DPC investigated the extent to which TikTok complies with the GDPR in relation to the processing of children's data. In this context, a number of settings, such as user profiles being public by default and age verification, were scrutinised. 

As a result of the investigation, TikTok was fined €345 million and given three months to correct the breaches identified in the decision.

22.09.2023

THE DUTCH DATA PROTECTION AUTHORITY WILL INVESTIGATE THE USE OF DATA BY ARTIFICIAL INTELLIGENCE:

The Dutch Data Protection Authority (AP) is conducting various investigations into the processing of personal data by artificial intelligence, with a particular focus on applications for children. In this context, the AP requested information from a technology company about the operation of a chatbot integrated into applications popular with children.

The AP, which also is a member of the EDPB's ChatGPT Committee, had previously asked OpenAI how it processes personal data for the ChatGPT system.

22.09.2023

DATATILSYNET PUBLISHES GUIDELINES ON EMPLOYEE ACCESS TO PERSONAL DATA:

Datatilsynet, Denmark's data protection authority, has published guidance on preventing unauthorised access to personal data by employees. 

The guidance states that employees should only be able to access data if there is a business need, that personal data used by employees should be recorded in order to detect misuse, and that companies should carry out a risk assessment to determine whether they have good practices in place.

22.09.2023

CALL TO ACTION FOR BUSINESSES BY INDIA'S MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY:

Rajeev Chandrasekhar, India's Minister of State for Electronics and Information Technology, has said that organisations will be expected to comply with the Digital Data Protection Act within one year. The Minister also stated that Indian DPA members will be appointed within 30 days and the organisation will be responsible for taking action against breaches of the law. 

In addition, he stated that data breaches will accumulate until the board is formed and these breaches will be addressed after the board is formed.

22.09.2023