{"id":10856,"date":"2025-07-02T14:48:51","date_gmt":"2025-07-02T12:48:51","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=10856"},"modified":"2025-07-03T12:51:09","modified_gmt":"2025-07-03T10:51:09","slug":"data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/","title":{"rendered":"Data protection digest\u00a0 17 Jun &#8211; 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">Risk Assessment<\/h4>\n\n\n\n<p>Personal data protection should be the cornerstone of risk assessments for organisations. The Polish regulator UODO came to this conclusion after investigating a ransom attack in a children&#8217;s clinical hospital in Bia\u0142ystok. Access to IT systems was blocked, which resulted in a breach of confidentiality and availability of personal data of approximately 2,000 employees, including the possibility of obtaining unauthorized access to them. In the circumstances of this case, the risk assessment was conducted on the basis of <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3803\">a flawed procedure &#8211; from the perspective of the hospital as an organisation, and not from the perspective of protecting data subjects.<\/a>&nbsp;<\/p>\n\n\n\n<p>The documents, which were supposed to prove that the risk analysis had been conducted, were inconsistent and full of ambiguities. The hospital did not indicate which processes it was analysing, nor did it link these processes to identified threats, vulnerabilities and the final risk assessment. When explaining what technical measures it used to secure its IT systems, the administrator referred to an audit conducted for compliance with the act on the national cybersecurity. However, this act focuses primarily on ensuring a safe and uninterrupted system for providing services, and not \u2013 as is the case with the GDPR \u2013 on protecting the rights and freedoms of natural persons.<\/p>\n\n\n\n<p>The hospital did not implement an appropriate procedure for performing and documenting recovery tests, and did not apply appropriate security measures for the backup copies created, which could have contributed to the fact that the hospital was unable to fully restore the data lost as a result of the attack.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><a href=\"#newslettersignup\"><mark class=\"has-inline-color has-vivid-purple-color\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/mark><\/a><\/h5>\n\n\n\n<h4 class=\"wp-block-heading\">Other legal developments<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdt60U-rgZpsscxy4WbV1KYwr5nJv22ni5DvfFFlSDsG3HBT-y5FopgQfnYr0l12vhOQfiMItXZ9j_gANfF-p7MxVfcUkq_iN1HHTZTB1G1w8RSyrYYgQh2EhXm4ob72L8TxAdqng?key=_MeIxJMdyKA5I3vdXXpFLg\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>From 19 June, the <strong>Data Use and Access Act 2025<\/strong> <a href=\"https:\/\/ico.org.uk\/about-the-ico\/what-we-do\/legislation-we-cover\/data-use-and-access-act-2025\/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations\/\">(DUAA) amends, but does not replace, the UK General Data Protection Regulation (UK GDPR)<\/a>, the Data Protection Act 2018 (DPA) and the Privacy and Electronic Communications Regulations (PECR), to promote innovation (eg, commercial scientific research, automated decision-making) and economic growth. Whilst it still protects people and their rights, the DUAA simplifies personal data usage in the following ways:\u00a0<\/p>\n<\/div><\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li>New \u2018recognised legitimate interests\u2019 lawful basis of data processing (from public safety to direct marketing)<\/li>\n\n\n\n<li>Assumption of compatibility for some data reuses<\/li>\n\n\n\n<li>\u2018Soft opt-in\u2019 (eg, for charities)<\/li>\n\n\n\n<li>More flexible requirements on cookies<\/li>\n\n\n\n<li>Reasonable and proportionate subject access requests, etc.<\/li>\n<\/ul>\n\n\n\n<p>At the same time, if you provide an online service that is likely to be used by children, the DUAA explicitly requires you to take their needs into account. The data subject complaints must also be facilitated by offering electronic complaint forms and respecting the 30-day legal time frame for acknowledgement and response. The changes will be phased in between June 2025 and June 2026. More summaries of changes can be found <a href=\"https:\/\/www.gov.uk\/guidance\/data-use-and-access-act-2025-data-protection-and-privacy-changes\">here<\/a> and <a href=\"https:\/\/ico.org.uk\/about-the-ico\/what-we-do\/legislation-we-cover\/data-use-and-access-act-2025\/the-data-use-and-access-act-2025-duaa-summary-of-the-changes\/\">here<\/a>.<\/p>\n\n\n\n<p><strong>GDPR enforcement ease:<\/strong> The Council of the European Union and the Parliament have reached a deal to make cross-border GDPR enforcement work better for citizens. Once adopted, the regulation will <a href=\"https:\/\/www.consilium.europa.eu\/en\/press\/press-releases\/2025\/06\/16\/data-protection-council-and-european-parliament-reach-deal-to-make-cross-border-gdpr-enforcement-work-better-for-citizens\/\">speed up the process of handling cross-border GDPR complaints, and any follow-up investigations<\/a>.&nbsp; The co-legislators agreed on an overall investigation deadline of 15 months, which can be extended by 12 months for the most complex cases. The early resolution mechanism will allow data protection authorities to resolve a case before triggering the standard procedures for handling a cross-border complaint. This may be the case where the company or organisation in question has addressed the infringement and where the complainant has not objected to the early resolution of the complaint.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">AI and web scraping<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXd_6hbQWpi0nKp3MeYUIsZ-R025WEmfSsv-NvZEl1NLAL3DUH1uoes2g4LKRkC1klQivlNl3Md9eTZrOTdOOyQJktXp7NiCph7rnJ7gAy77EyY7yGNoCfQRE9I6H2IwpAIh_vWdqQ?key=_MeIxJMdyKA5I3vdXXpFLg\" alt=\"risk assessment\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The GDPR, in many cases, applies to AI models trained on personal data, due to their memorisation capabilities. To that end, a French CNIL guide specifies the conditions for using legitimate interest in the development of AI in the case of web scraping.&nbsp; In line with the opinion adopted by the EDPB in December 2024, the CNIL considers that the development of AI systems <a href=\"https:\/\/www.cnil.fr\/fr\/recommandations-developpement-ia-interet-legitime\">does not systematically require the consent of individuals. Legitimate interest is a possible legal basis<\/a> for the development of AI systems, subject to strong safeguards.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>The guide offers examples of concrete safeguards adapted to the different types of AI systems: exclusion of certain data from collection, increased transparency, facilitation of the exercise of data subject rights, etc. For example, the reuse of future conversations of users with a chatbot for the improvement of the AI model can be based on legitimate interest provided that certain strong guarantees are put in place: information for individuals, right to object, restriction of processing towards pseudonymised\/anonymised data, etc.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities worldwide<\/h4>\n\n\n\n<p><strong>COPPA update:<\/strong> In the US, the amended Children&#8217;s Online Privacy Protection Rule took effect on 23 June. It includes a new definition for a <a href=\"https:\/\/www.federalregister.gov\/documents\/2025\/04\/22\/2025-05904\/childrens-online-privacy-protection-rule\">mixed audience website<\/a> or online service that is intended to provide greater clarity regarding an existing sub-category of child-directed  services. The amendments also modify operators&#8217; obligations concerning direct and online notices; information security, deletion, and retention protocols; annual assessment, disclosure, and reporting requirements. It also adopts rules related to parental consent requirements, methods of obtaining verifiable parental consent, and exceptions.&nbsp;<\/p>\n\n\n\n<p><strong>Biometric identifiers vs biometric data:<\/strong> The JDSupra legal blog explains the <a href=\"https:\/\/www.jdsupra.com\/legalnews\/colorado-expands-reach-of-obligations-5522997\/\">differences between the two categories<\/a>, specified in the Colorado Privacy Act, which went into effect on July 1: <strong>Biometric identifiers<\/strong> is data generated by the technological processing, measurement, or analysis of a consumer\u2019s biological, physical, or behavioral characteristics which can be processed for identification. <strong>Biometric data<\/strong> is a subset of biometric identifiers which are used or intended to be used for identification purposes. It does not include digital or physical photographs, audio or voice recordings, or any data generated from a digital or physical photograph or an audio or video recording unless any of these are used for identification purposes.&nbsp;Both categories can be considered sensitive data and can require a privacy notice and consent.&nbsp;<\/p>\n\n\n\n<p><strong>Child data: <\/strong>Also in the US, New York\u2019s Child Data Protection Act (NYCDPA) went into effect on June 20. The Office of the Attorney General issues the <a href=\"https:\/\/ag.ny.gov\/sites\/default\/files\/2025-05\/nycdpa-guidance.pdf\">practical guidance<\/a> in advance concerning the application of NYCDPA to minors&#8217; data and the federal COPPA Rules; operator responsibilities concerning user-provided age flags; requirements for schools, school districts, and their third-party contractors; parental requests for products and services, etc. The guidance refers to a website, online service, online application, mobile application, or connected devices directed at minors.&nbsp;<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_c8a2ede0e5b25ce7e66cbb1729534dee\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email     <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">DeepSeek AI<\/h4>\n\n\n\n<p>Germany&#8217;s data protection commissioner has asked <a href=\"https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/deepseek-faces-expulsion-app-stores-germany-2025-06-27\/\">Apple and Google to remove Chinese AI startup DeepSeek<\/a> from their app stores in the country due to concerns about data protection, Reuters reports. According to its <a href=\"https:\/\/cdn.deepseek.com\/policies\/en-US\/deepseek-privacy-policy.html\">privacy policy<\/a>, DeepSeek stores numerous pieces of personal data, such as requests to its AI or uploaded files, on computers in China. The commissioner took the decision after asking DeepSeek in May to meet the requirements for non-EU data transfers or else voluntarily withdraw its app. DeepSeek did not comply with this request. Across Europe the authorities have also been evaluating the app, but while Italy has completely blocked it on app stores, the UK government said that the use of DeepSeek remains a personal choice for members of the public.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In other news<\/h4>\n\n\n\n<p><strong>Data access requests:<\/strong> The Swiss FDPIC concluded its investigation into Cembra Money Bank AG. After receiving complaints, the privacy regulator contacted Cembra with a view to a low-threshold intervention. Cembra replied that <a href=\"https:\/\/www.edoeb.admin.ch\/en\/ruling-cembra-money-bank-ag\">due to staff shortages, responses to requests for information were delayed<\/a>. The company was reminded of the legal deadline for responding to requests for information within 30 days. The regulator also ordered the bank to provide all persons who had previously received only a standardised response to their requests with the actual information on their personal processed data.&nbsp;<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcRt3XHRZ3XDX4grVtdqjVWp5KO2anRl_BELEQPYt-IKHdFlB4R8XK8jQsCePcdxtrwjmSsLtXLxoCKNvoO0cXBlM2vO157NViSj8fkgj6deA6_TGRTtYpwucV7dnpC7kSYpW_Vww?key=_MeIxJMdyKA5I3vdXXpFLg\" alt=\"risk assessment\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Telemarketing and data subject rights: <\/strong>An organisation must provide the most important information about the processing of personal data immediately during the first direct marketing call, if it has obtained the person&#8217;s contact information from somewhere other than itself, states the Finnish data protection authority. If a person submits a request to delete their data to customer service, <a href=\"https:\/\/tietosuoja.fi\/-\/henkilotietojen-kasittelysta-tulee-informoida-myos-puhelinmarkkinoinnissa\">the request cannot be left unprocessed because it has not been submitted to the data protection officer<\/a>. <\/p>\n<\/div><\/div>\n\n\n\n<p>The organisation must ensure that the request is transferred to the party that processes it. The same applies to the prohibition of direct marketing: If a person wants to prohibit direct marketing during a call, the request cannot be bypassed by giving instructions for prohibiting it.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Unjust dismissal<\/h4>\n\n\n\n<p>The<strong> <\/strong>Italian regulator Garante fined Autostrade per l&#8217;Italia Spa 420,000 euros for having unlawfully processed the personal data of an employee, which was then used to justify her dismissal.&nbsp; The authority&#8217;s intervention followed the complaint of the worker who had reported the use, by the company, of <a href=\"https:\/\/www.garanteprivacy.it\/garante\/doc.jsp?ID=10143261\">content extracted from her Facebook profile and private chats on Messenger and WhatsApp to justify the disciplinary proceedings<\/a>&nbsp; against her. The content used also included excerpts of comments and photo descriptions in quotation marks.&nbsp;<\/p>\n\n\n\n<p>The investigations revealed that the content had been used by the employer without a valid legal basis, through screenshots provided by some colleagues and a third party, present among the employee&#8217;s &#8220;friends&#8221; on Facebook and active in her private conversations on Messenger and WhatsApp. Furthermore, the communications concerned opinions and exchanges that took place in contexts outside the employment relationship, not relevant for the purposes of assessing professional suitability.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">AI prohibited practices in the gaming sector<\/h4>\n\n\n\n<p>The Maltese data protection authority IDPC warns us that AI systems used for player profiling, personalised gaming experiences and monetisation are not just subject to Art. 22 of the GDPR, which restricts automated decisions that carry legal or similarly significant implications for individuals, but are also <a href=\"https:\/\/techgdpr.com\/blog\/how-to-build-trustworthy-ai-from-the-ground-up-with-privacy-by-design\/\">high-risk under the AI Act<\/a> so as to qualify them as prohibited practices. <a href=\"https:\/\/idpc.org.mt\/news-latest\/idpc-legal-counsel-flags-ai-concerns-in-gaming-sector-at-mdia-panel\/\">Manipulative AI<\/a> deploys subliminal or deceptive techniques with the object of distorting player behaviour by impairing their ability to make an informed decision, causing them to take a decision they would have otherwise not taken, (for eg, AI powered algorithms which regulate emotion-triggered loot boxes which distort player behaviour).&nbsp;<\/p>\n\n\n\n<p>Other prohibited techniques in the gaming sector are <a href=\"https:\/\/idpc.org.mt\/news-latest\/idpc-legal-counsel-flags-ai-concerns-in-gaming-sector-at-mdia-panel\/\">exploitation of vulnerabilities and social scoring<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In case you missed it&nbsp;<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdaB66H1nSUT6wExblAgtspHL99v-cYXTZ0eb7lHUQYdPRCKfHUT1m5eevt_9nasfD8njCqWILLrNHYu80H8Der8fmxg2nGoZQlzv_W_LUFK1pjHDUv3v0Uvtq6H9qEjPTafmwO4Q?key=_MeIxJMdyKA5I3vdXXpFLg\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Video integration into websites: <\/strong>Germany\u2019s Federal Commissioner for Data Protection and Freedom of Information (BfDI) has carried out an automated website check for the first time and identified violations in the integration of YouTube videos on federal websites. YouTube videos can be used by public authorities and others on their websites in compliance with data protection regulations. However, this becomes problematic when videos are embedded directly.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p><a href=\"https:\/\/www.bfdi.bund.de\/SharedDocs\/Kurzmeldungen\/DE\/2025\/13-teilautomatisierte-Webseitenpr%C3%BCfung.html\">When the website is accessed, the user&#8217;s browser automatically connects to YouTube servers and transmits, among other things, IP addresses<\/a>. This data transfer takes place without the user&#8217;s prior consent and thus violates the Telecommunications Digital Services Data Protection Act (TDDDG). For implementing video integration in compliance with data protection regulations, the BfDI offers two other options:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Self-hosting is the gold standard: <\/strong>Videos are hosted on your own servers and embedded on the website. This ensures complete control over data processing and user interactions.<\/li>\n\n\n\n<li><strong>Two-click solutions:<\/strong> Users must actively click on a preview image before the connection to YouTube is established. (With this option, an equivalent alternative without a third-party provider should always be offered).<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Risk Assessment Personal data protection should be the cornerstone of risk assessments for organisations. The Polish regulator UODO came to this conclusion after investigating a ransom attack in a children&#8217;s clinical hospital in Bia\u0142ystok. Access to IT systems was blocked, which resulted in a breach of confidentiality and availability of personal data of approximately 2,000 [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":10857,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[51,122,98,58,322],"class_list":["post-10856","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-artificial-intelligence","tag-data-subject-access-requests","tag-direct-marketing","tag-gdpr-compliance","tag-risk-assessment"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg",1280,583,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-300x137.jpg",300,137,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-768x350.jpg",640,292,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-1024x466.jpg",640,291,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg",1280,583,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg",1280,583,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>Risk Assessment Personal data protection should be the cornerstone of risk assessments for organisations. The Polish regulator UODO came to this conclusion after investigating a ransom attack in a children&#8217;s clinical hospital in Bia\u0142ystok. Access to IT systems was blocked, which resulted in a breach of confidentiality and availability of personal data of approximately 2,000 employees, including the possibility of obtaining unauthorized access to them. In the circumstances of this case, the risk assessment was conducted on the basis of a flawed procedure &#8211; from the perspective of the hospital as an organisation, and not from the perspective of protecting&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg",1280,583,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-300x137.jpg",300,137,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-768x350.jpg",640,292,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-1024x466.jpg",640,291,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg",1280,583,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg",1280,583,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>Risk Assessment Personal data protection should be the cornerstone of risk assessments for organisations. The Polish regulator UODO came to this conclusion after investigating a ransom attack in a children&#8217;s clinical hospital in Bia\u0142ystok. Access to IT systems was blocked, which resulted in a breach of confidentiality and availability of personal data of approximately 2,000 employees, including the possibility of obtaining unauthorized access to them. In the circumstances of this case, the risk assessment was conducted on the basis of a flawed procedure &#8211; from the perspective of the hospital as an organisation, and not from the perspective of protecting&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest\u00a0 17 Jun - 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the important data-related stories: protecting individuals, not organisations, should be the focus of risk assessment\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest\u00a0 17 Jun - 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the important data-related stories: protecting individuals, not organisations, should be the focus of risk assessment\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-02T12:48:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-03T10:51:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"583\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest\u00a0 17 Jun &#8211; 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment\",\"datePublished\":\"2025-07-02T12:48:51+00:00\",\"dateModified\":\"2025-07-03T10:51:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/\"},\"wordCount\":1890,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/airport-8676548_1280.jpg\",\"keywords\":[\"Artificial Intelligence\",\"data subject access requests\",\"direct marketing\",\"GDPR Compliance\",\"risk assessment\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/\",\"name\":\"Data protection digest\u00a0 17 Jun - 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/airport-8676548_1280.jpg\",\"datePublished\":\"2025-07-02T12:48:51+00:00\",\"dateModified\":\"2025-07-03T10:51:09+00:00\",\"description\":\"TechGDPR\u2019s review of the important data-related stories: protecting individuals, not organisations, should be the focus of risk assessment\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/airport-8676548_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/airport-8676548_1280.jpg\",\"width\":1280,\"height\":583,\"caption\":\"risk assessment\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest\u00a0 17 Jun &#8211; 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest\u00a0 17 Jun - 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment - TechGDPR","description":"TechGDPR\u2019s review of the important data-related stories: protecting individuals, not organisations, should be the focus of risk assessment","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest\u00a0 17 Jun - 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment - TechGDPR","og_description":"TechGDPR\u2019s review of the important data-related stories: protecting individuals, not organisations, should be the focus of risk assessment","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/","og_site_name":"TechGDPR","article_published_time":"2025-07-02T12:48:51+00:00","article_modified_time":"2025-07-03T10:51:09+00:00","og_image":[{"width":1280,"height":583,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest\u00a0 17 Jun &#8211; 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment","datePublished":"2025-07-02T12:48:51+00:00","dateModified":"2025-07-03T10:51:09+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/"},"wordCount":1890,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg","keywords":["Artificial Intelligence","data subject access requests","direct marketing","GDPR Compliance","risk assessment"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/","name":"Data protection digest\u00a0 17 Jun - 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg","datePublished":"2025-07-02T12:48:51+00:00","dateModified":"2025-07-03T10:51:09+00:00","description":"TechGDPR\u2019s review of the important data-related stories: protecting individuals, not organisations, should be the focus of risk assessment","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/07\/airport-8676548_1280.jpg","width":1280,"height":583,"caption":"risk assessment"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-02072025-protecting-individuals-not-organisations-should-be-the-focus-of-risk-assessment\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest\u00a0 17 Jun &#8211; 1 Jul 2025: protecting individuals, not organisations, should be the focus of risk assessment"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/10856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=10856"}],"version-history":[{"count":20,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/10856\/revisions"}],"predecessor-version":[{"id":10879,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/10856\/revisions\/10879"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/10857"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=10856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=10856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=10856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}