Data breach notification period: (no) problems with the calculation?

Meldefrist bei Datenschutz-Verletzung

Data Breach Notification Period Pursuant to Article 33 para. 1 of the General Data Protection Regulation (GDPR), the controller must notify the competent supervisory authority of a personal data breach without undue delay and, if possible, within 72 hours of becoming aware of it. But how is the data breach notification period calculated? Applicable Standards … Read more

IoT (Internet of Things) and Data Protection

Mann

IoT and Data Protection Smart technologies are increasingly finding their way into the daily lives of many people, whether out of affinity for technology, practicality or convenience. In the context of the Internet of Things (IoT) and the Industrial Internet of Things (IIoT), the networking of a wide variety of devices is steadily increasing. However, … Read more

Reject all Cookies?

Frau möchte am Smartphone Cookies ablehnen / A woman wants to reject all cookies

Should there be a “reject all cookies” button in the cookie banner? Many people find the banners that ask for consent to the use of various cookies when visiting a website annoying. A “reject all cookies” button does not exist on many websites. Rather, you have to navigate through a settings menu and disable the … Read more

Data Protection and WhatsApp Business Cloud API

WhatsApp Business Cloud API; Data Protection and WhatsApp

Data Protection and WhatsApp As a daughter company of Meta (formerly Facebook), WhatsApp has often been criticized because of massive concerns about data protection and privacy. Despite all the data protection concerns: according to studies (including here), 85 percent of customers would like to be able to contact companies via WhatsApp. Due to the popularity … Read more

Controller-Controller Agreement

Controller-Controller-Vertrag Abschluss unter Einhaltung der DSGVO zwischen zwei Personen an einem Schreibtisch. / Signing a Controller-Controller Agreement.

Is a contract necessary between controllers who are not joint controllers? If personal data is exchanged between companies or if two or more companies use a common data pool, which is often found in group constellations, the GDPR regulates two case constellations: processor (Art. 28 GDPR) and joint controllers (Art. 26 GDPR). A company is … Read more