{"id":11201,"date":"2025-10-05T14:36:21","date_gmt":"2025-10-05T12:36:21","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=11201"},"modified":"2025-10-05T14:36:22","modified_gmt":"2025-10-05T12:36:22","slug":"data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/","title":{"rendered":"Data protection digest 17 Sep &#8211; 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">GDPR compensations<\/h4>\n\n\n\n<p>In Denmark, an individual has been awarded financial compensation for non-material damage resulting from a data breach (Art. 82 of the GDPR). A High Court ruled on 20 August, that a woman should receive approx. <a href=\"https:\/\/www.datatilsynet.dk\/presse-og-nyheder\/nyhedsarkiv\/2025\/sep\/ny-dansk-dom-kan-aendre-praksis-for-erstatning-efter-gdpr\">335 euros in compensation after a municipality mistakenly shared her health information with a third party<\/a>. The decision has been appealed to the Supreme Court, where the woman and her lawyer will, among other things, try to have the GDPR compensations increased and awarded to her spouse as well.&nbsp;<\/p>\n\n\n\n<p>Until now, Danish practice has been that claims for compensation without financial loss must be assessed according to the provisions of the Danish Civil Liability Act. The court has generally required a qualified damage effect. The decision from August could, if upheld by the Supreme Court, be a new breakthrough in Danish law and possibly the European law. The compensation of 335 is a small amount, but if thousands of citizens choose to file a lawsuit in connection with the same breach \u2013 for example via a class action \u2013 the consequences for companies and authorities could be extensive.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><mark style=\"background-color:#f9e6af;color:#b577ef\" class=\"has-inline-color\"><a href=\"#newslettersignup\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/a><\/mark><\/h4>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>EU-US data transfers and immigration control<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3-1024x682.png\" alt=\"\" class=\"wp-image-11208 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3-1024x682.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3-300x200.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3-768x512.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>On 17 September, the European Data Protection Supervisor (EDPS) issued an <a href=\"https:\/\/www.edps.europa.eu\/data-protection\/our-work\/publications\/opinions\/2025-09-17-edps-opinion-242025-recommendation-council-authorising-opening-negotiations-framework-agreement-between-eu-and-usa-exchange-information_en\">Opinion on a framework agreement between the EU and the US on the exchange of information for security screenings<\/a> and identity verifications. Individual Member States would be empowered to sign bilateral agreements for the exchange of data from their national systems. It would be the first agreement concluded by the EU to entail the large-scale sharing of personal data, including biometric data (fingerprints), for border and immigration control purposes with a third country. <\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<p><strong>Data transfers for medical research: <\/strong>The German Data Protection Conference (DSK) adopted a paper on data transfers to third countries for scientific research in the medical sector. The admissibility of transferring personal data to third countries under data protection law cannot be assessed in general terms, but only on a case-by-case basis, as numerous circumstances play a role in the assessment. This also applies to scientific research for medical purposes. It must always be examined whether the data subjects have been adequately informed about the (intended) transfer in accordance with the GDPR. In scientific research for medical purposes, broad consent is an established legal basis for data processing. Since there may be <a href=\"https:\/\/www.datenschutzkonferenz-online.de\/media\/oh\/20250917_DSK_OH_Datenuebermittlungen.pdf\">special interactions between Broad Consent and the basis for transfer under the GDPR<\/a>, these are explained in detail in the DSK paper (in German).&nbsp;<\/p>\n\n\n\n<p><strong>The European Innovation Act:<\/strong> The European Commission concluded its consultation and evidence-gathering for an impact assessment to assist in the creation of the European Innovation Act. The Commission seeks information on <a href=\"https:\/\/digitalpolicyalert.org\/event\/31741-european-commission-closes-consultation-on-european-innovation-act\">ways to overcome obstacles that innovative entities encounter, including fragmented regulations, restricted access to infrastructure and funding<\/a>, underutilised innovation procurement, and inadequate commercialisation of findings from publicly funded research and innovation. The Act aims to create sector-wide horizontal conditions as opposed to sector-specific programs.&nbsp;<\/p>\n\n\n\n<p><strong>Political online targeting ban in the EU: <\/strong><a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/ap-wijst-politieke-partijen-op-nieuwe-regels-voor-online-politieke-reclame\">Political parties will soon be prohibited from targeting voters online<\/a> with political advertisements. A new European regulation on the Transparency and&nbsp;Targeting&nbsp;of&nbsp;Political&nbsp;Advertising (TTPA) will take effect on 10 October. It aims to prevent voters from being secretly influenced during election campaigns and to undermine trust in fair elections, which can involve the processing of personal data.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>LinkedIn AI training<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"731\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1024x731.png\" alt=\"\" class=\"wp-image-11202 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1024x731.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-300x214.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-768x548.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>Users who do not want LinkedIn to use their data to train AI models must disable this before 3 November. The European data protection authorities are urging people to do so. This data includes profile information and public content shared in the past. Once this data is in LinkedIn&#8217;s AI systems, it will be impossible to retrieve, and users will lose control over their data. All LinkedIn users&#8217; data will automatically be used for AI training unless the setting is actively disabled. <\/p>\n<\/div><\/div>\n\n\n\n<p>Anyone who does not want personal data used for LinkedIn AI training must opt \u200b\u200bout before 3 November via this <a href=\"https:\/\/www.linkedin.com\/mypreferences\/d\/settings\/data-for-ai-improvement\">link<\/a> or in the app under <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/ap-bezorgd-over-ai-training-linkedin-en-roept-gebruikers-op-om-instellingen-aan-te-passen\">&#8220;Settings &amp; Privacy &gt; Data Privacy &gt;Data for Generative AI Improvement&#8221; and disable the switch.<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Vehicle data in the era of the Data Act<\/strong><\/h4>\n\n\n\n<p>On 12 September, the European Commission published the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/guidance-vehicle-data-accompanying-data-act\">\u201cGuidance on Vehicle Data, accompanying the Data Act.\u201d<\/a> The document defines the categories of data falling within the scope of he regulation and outlines the access rights granted to users and to third parties designated by them. It clarifies, first of all, that a vehicle qualifies as a \u201cconnected product\u201d when it meets two cumulative requirements: <a href=\"https:\/\/news.cms.law\/rv\/ff00f512efb6371e485be48ba645adf739948d59?utm_source=Concep%20Send&amp;utm_medium=email&amp;utm_campaign=CMS+Newsletter+%7c+%22Vehicle+data%22+nell%27+era+del+Data+Act.+Le+Linee+guida+della+Commissione+UE_09%2f25%2f2025\">it must generate or collect data concerning its use or its surrounding environment, and it must have the ability to communicate such data via an electronic communications service<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<p><strong>&#8216;Neighbour&#8217;s camera&#8217; a major annoyance: <\/strong>The Dutch data protection uthority (DPA) is receiving a growing number of complaints from people concerned about their privacy due to their neighbours&#8217; doorbells or security cameras. The regulator wants to prevent the improper use of doorbell cameras as much as possible. Therefore, the DPA is <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/camera-van-de-buren-grote-ergernis-ap-wil-preventieve-aanpak-deurbelcameras\">urging manufacturers to configure doorbell cameras to be privacy-friendly by default<\/a>. It also wants to raise consumer awareness, for example, by providing information about what is and isn&#8217;t permitted.&nbsp;<\/p>\n\n\n\n<p><strong>AI risks in the health profession: <\/strong>A bill sponsored by the California Medical Association (CMA) that addresses dangers associated with the use of AI in health care has passed out of the Legislature and is headed for the Governor\u2019s signature. It prohibits AI systems from being misrepresented as licensed medical professionals and provides California\u2019s state health profession boards with the authority to enforce title protections for health care workers, ensure that new <a href=\"https:\/\/www.cmadocs.org\/newsroom\/news\/view\/ArticleId\/50982\/CMA-sponsored-bill-to-protect-patients-from-misleading-AI-chatbots-heads-to-Governor-s-desk\">technologies in health care are deployed in ways that protect patient safety, preserve trust, and support the physician-patient relationship<\/a>.&nbsp;<\/p>\n\n\n\n<p><strong>Medical records: <\/strong>The Swiss FDPIC has published a factsheet on the forms that are given to patients to sign when they go to the doctor. It takes account of the various opinions expressed on the subject and aims to clarify a number of issues raised by these forms: a) the distinction between the duty to provide information on data collection and the issue of patient consent to data processing; b) secure data communication; c) the question of proportionality, regarding what data a patient can legitimately be asked to provide. The <a href=\"https:\/\/www.edoeb.admin.ch\/en\/actsheet-on-the-forms-that-are-given-to-patients\">document is available in English<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Digital communication and minors<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1-1024x683.png\" alt=\"\" class=\"wp-image-11204 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1-1024x683.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1-300x200.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1-768x512.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>In France, the regulatory authority for audiovisual and digital communication (Arcom) released the results of its study on online risks for minors,&nbsp; digitalpolicyalert.org reports. Over <a href=\"https:\/\/digitalpolicyalert.org\/event\/33778-regulatory-authority-for-audiovisual-and-digital-communication-released-study-on-minors-online-what-risks-what-protections-and-regulatory-priorities-on-protection-of-minors-online\">four out of five children use at least one extremely major internet platform on a daily basis<\/a>, according to the study. 42 per cent of minors use social networks before the age of 13 by lying about their age, and the average age of initial use is 12 years old. <\/p>\n<\/div><\/div>\n\n\n\n<p>According to the study, 83 per cent of children are regularly exposed to at least one of the six risks: harmful or shocking content, cyberbullying, dangerous challenges, malicious adult contact, and online scams.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>E-health data security<\/strong><\/h4>\n\n\n\n<p>The European Union Agency for Cybersecurity (ENISA) has published a <a href=\"https:\/\/www.enisa.europa.eu\/news\/ehealth-security-in-the-spotlight-a-good-practice-guide-for-a-robust-and-resilient-eu-health-sector\">good practice guide to support entities of the health sector<\/a> in strengthening their digital security. The health sector is classified among those in the risk zone, highlighting a significant gap between its cybersecurity maturity and its critical importance: medical systems and data have become growing targets of cybercrime, with ransomware and phishing campaigns on the rise.&nbsp;These actionable practices are designed to be simple to implement and enhance the preparedness and security of all types of health entities, from hospitals and service providers to individual medical specialists. The recommendations cover areas such as systems and network protection, safeguarding devices and patient data, addressing challenges in the ICT supply chain.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Reporting AI incidents<\/strong><\/h4>\n\n\n\n<p>The European<strong> <\/strong>Commission<strong> <\/strong>has issued draft guidance and a reporting <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/consultations\/ai-act-commission-issues-draft-guidance-and-reporting-template-serious-ai-incidents-and-seeks\">template on serious AI incidents.<\/a> Under the EU AI Act, providers of high-risk AI systems will be required to report serious incidents to national authorities. This new obligation, set out in Art. 73, aims to detect risks early, ensure accountability, enable quick action, and build public trust in AI technologies.&nbsp;While the rules will only become applicable from August 2026, you can already download the draft guidance and reporting template below. Both these documents will help providers to prepare. The draft guidance clarifies definitions, offers practical examples, and explains how the new rules relate to other legal obligations.&nbsp;<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_9c4b79e031392c4615b047915ef8999f\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email     <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Drone use and personal data<\/strong><\/h4>\n\n\n\n<p>The Latvian data protection authority elaborated on this topic, which is becoming increasingly popular today as drones are <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-drona-izmantosana-kas-jazina-par-personas-datu-apstradi\">used in defence, business, and people&#8217;s private lives<\/a>. Personal data processing occurs when materials are obtained with the help of a drone that can identify a specific person. Therefore, it is not possible to say with certainty that personal data processing is performed in all cases when a drone comes into view of a person. If the materials are intended to be distributed publicly, this processing may be justified based on legitimate interests. This may be done after a balancing of interests, in which the proportionality of the processing in relation to the interests of the people depicted is assessed. Similarly, the use of drones may, in some cases, be linked to the public interest, as well as processing for journalistic purposes.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Video games and personal accounts<\/strong><\/h4>\n\n\n\n<p> In the audiovisual and video game sectors, the purchase of digital content can justify a long retention of data. The French CNIL reminds professionals of the rules to follow to manage inactive accounts while respecting the rights of users. Professionals must guarantee uninterrupted access to purchased digital content, as provided for in consumer law. In the audiovisual and video game sector, this access often goes through a personal account that acts as a video library, allowing the user to find their movies, series or games at any time. The <a href=\"https:\/\/www.cnil.fr\/fr\/achat-de-contenus-numeriques-quelle-duree-de-conservation-des-comptes-inactifs\">deletion of accounts for which no action has been taken by users for two years is considered proportionate<\/a>.&nbsp;It is recommended that affected users be notified before this deadline to allow them to keep their accounts active.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u2018Facial boarding\u2019 at airport<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-1024x1024.png\" alt=\"\" class=\"wp-image-11206 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-1024x1024.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-300x300.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-150x150.png 150w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-768x768.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-200x200.png 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>Italian data protection regulator Garante has recently <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/10167973\">blocked the use of facial recognition in Italian airports<\/a> (so-called face boarding), with the provision adopted against Societ\u00e0 per Azioni Esercizi Aeroportuali, to suspend the use of the specific technological solution adopted, since it is incompatible with the GDPR. Garante specifies that the use of facial recognition technologies at airports in principle is permitted, but requires technological solutions that balance the need for simplified boarding procedures with the need to protect personal data in compliance with current European regulations, particularly regarding the processing of biometric data.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">In other news<\/h3>\n\n\n\n<p><strong>Automated-decision fine: <\/strong>The Hamburg Data Protection Commissioner HmbBfDI has imposed a fine of almost 500,000 euros on a financial company for violations of the rights of affected customers in automated decisions in individual cases. Despite good credit ratings, several <a href=\"https:\/\/datenschutz-hamburg.de\/news\/zwischenbilanz-2025-hmbbfdi-verhaengt-bussgelder-von-insgesamt-775000-euro\">customers&#8217; credit card applications were rejected based on automated decisions<\/a>, decisions made by machines based on algorithms and without human intervention. When the affected customers subsequently demanded a reason for the rejected applications, the company failed to adequately fulfill its statutory information and disclosure obligations.&nbsp;<\/p>\n\n\n\n<p><strong>Hospital data fine: <\/strong>The Italian regulator Garante has fined a <a href=\"https:\/\/www.garanteprivacy.it\/garante\/doc.jsp?ID=10166336\">university hospital 80,000 euros for failing to properly configure its health records<\/a>. The hospital used two applications, on patients and hospitalisation records, through which all healthcare personnel could conduct searches on patients&#8217; medical histories, even if they were not involved in their treatment. They did not include adequate access profiling measures or security measures such as alerts or tracking of operations performed on the applications in dedicated log files.&nbsp;Furthermore, patients were unaware of the existence of the treatments performed through the records and were therefore unable to give or deny their consent to their records or decide whether to obscure certain information, such as that subject to greater protection.<\/p>\n\n\n\n<p><strong>HIPAA violation: <\/strong>A 182,000 dollar settlement has been agreed between the HHS\u2019 Office for Civil Rights and five Delaware healthcare providers to resolve alleged violations of the HIPAA Privacy and HIPAA Breach Notification Rules. The settlement concerns the <a href=\"https:\/\/www.hipaajournal.com\/cadia-healthcare-hipaa-settlement\/\">posting of patients\u2019 protected health information (PHI) on social media without first obtaining HIPAA-compliant authorizations<\/a> to use PHI for a purpose not expressly permitted by the HIPAA Privacy Rule, then failing to notify individuals about the impermissible use and disclosure.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Candid cameras against theft<\/strong><\/h4>\n\n\n\n<p>The French CNIL fined SAMARITAINE, which operates the store of the same name, 100,000 euros for concealing cameras in the store&#8217;s reserves. In 2023, due to the increase in cargo thefts from its reserves, SAMARITAINE placed new cameras in two reserves. These <a href=\"https:\/\/www.cnil.fr\/fr\/cameras-dissimulees-la-cnil-sanctionne-la-samaritaine\">cameras were disguised as smoke detectors and made it possible to record sound<\/a>. Discovered by employees, the cameras were removed shortly after that. In principle, in order to meet the requirement of loyalty, video surveillance filming employees must be visible and not concealed.&nbsp;However, in exceptional circumstances and under certain conditions, the data controller can temporarily install cameras that are not visible to employees. The company did report the existence of thefts committed in the reserves and explained that the device was temporary (which the technical characteristics of the device seem to confirm). <\/p>\n\n\n\n<p>It nevertheless did not carry out any prior analysis of compliance with the GDPR, nor documented the temporary nature of the installation.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In case you missed it<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-1024x1024.png\" alt=\"\" class=\"wp-image-11210 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-1024x1024.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-300x300.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-150x150.png 150w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-768x768.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-200x200.png 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Human oversight in AI:<\/strong> EDPS\u2019s latest TechDispatch episode explores the human oversight of Automated Decision-Making. While human oversight can occur at different stages of an AI system\u2019s lifecycle, including before deployment (ex-ante), real-time oversight on system operations is considered the one that can be most consequential, when <a href=\"https:\/\/www.edps.europa.eu\/data-protection\/our-work\/publications\/techdispatch\/2025-09-23-techdispatch-22025-human-oversight-automated-making_en\">an operator can still review the system\u2019s behaviour and intervene before its output takes effect<\/a>, helping to prevent potential harm to human lives or infringements on individuals\u2019 fundamental rights.<\/p>\n<\/div><\/div>\n\n\n\n<p><strong>Dark Net:<\/strong> Sweden\u2019s privacy protection authority IMY answers questions about how data controllers should handle developments following an IT attack where personal data was published on the Darknet. It is <a href=\"https:\/\/www.imy.se\/nyheter\/personuppgiftsansvarigas-roll-med-anledning-av-miljodata-och-darknet\/\">NOT recommended to search for or download the information published on the Darknet<\/a>: the files found may contain, for example, additional malware.  It also recommends that the organisations first and foremost, and in accordance with your data processor agreement, contact your data processor. Plus, organisations have a duty to notify the impacted data subjects of the personal data breach as soon as possible, as there is a high risk to the rights and freedoms of natural persons.&nbsp;<\/p>\n\n\n\n<p><strong>Patients&#8217; data and AI boom:<\/strong> Privacy international reports a boom for the UK\u2019s technology sector, with American tech firms collectively investing <a href=\"https:\/\/www.gov.uk\/government\/news\/us-uk-pact-will-boost-advances-in-drug-discovery-create-tens-of-thousands-of-jobs-and-transform-lives\">billions of pounds into the UK\u2019s AI and tech infrastructure<\/a>. The UK government hailed these investments as an element of a new <a href=\"https:\/\/www.gov.uk\/government\/news\/us-uk-pact-will-boost-advances-in-drug-discovery-create-tens-of-thousands-of-jobs-and-transform-lives\">\u2018Tech Prosperity Deal\u2019<\/a>. A key area mentioned as part of it is healthcare. Last summer, the UK released its 10 year health plan, which emphasised the centrality of technology, innovation and AI for the National Health Service. The plan states that to move the NHS into the 21st century, its unique advantages will be used, <a href=\"https:\/\/privacyinternational.org\/news-analysis\/5680\/patient-data-and-healthcare-ai-boom\">including the NHS\u2019s \u2018world-leading data\u2019<\/a>.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GDPR compensations In Denmark, an individual has been awarded financial compensation for non-material damage resulting from a data breach (Art. 82 of the GDPR). A High Court ruled on 20 August, that a woman should receive approx. 335 euros in compensation after a municipality mistakenly shared her health information with a third party. The decision [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":11212,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94,88],"tags":[51,129,58,258,79],"class_list":["post-11201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","category-gdpr","tag-artificial-intelligence","tag-consumer-data-protection","tag-gdpr-compliance","tag-health-related-data","tag-international-transfers"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg",1280,960,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-300x225.jpg",300,225,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-768x576.jpg",640,480,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-1024x768.jpg",640,480,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg",1280,960,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg",1280,960,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>GDPR compensations In Denmark, an individual has been awarded financial compensation for non-material damage resulting from a data breach (Art. 82 of the GDPR). A High Court ruled on 20 August, that a woman should receive approx. 335 euros in compensation after a municipality mistakenly shared her health information with a third party. The decision has been appealed to the Supreme Court, where the woman and her lawyer will, among other things, try to have the GDPR compensations increased and awarded to her spouse as well.&nbsp; Until now, Danish practice has been that claims for compensation without financial loss must&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg",1280,960,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-300x225.jpg",300,225,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-768x576.jpg",640,480,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-1024x768.jpg",640,480,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg",1280,960,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg",1280,960,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>GDPR compensations In Denmark, an individual has been awarded financial compensation for non-material damage resulting from a data breach (Art. 82 of the GDPR). A High Court ruled on 20 August, that a woman should receive approx. 335 euros in compensation after a municipality mistakenly shared her health information with a third party. The decision has been appealed to the Supreme Court, where the woman and her lawyer will, among other things, try to have the GDPR compensations increased and awarded to her spouse as well.&nbsp; Until now, Danish practice has been that claims for compensation without financial loss must&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 17 Sep - 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: New Danish court ruling may change practice for GDPR compensations\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 17 Sep - 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: New Danish court ruling may change practice for GDPR compensations\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-05T12:36:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-05T12:36:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"960\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 17 Sep &#8211; 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations\",\"datePublished\":\"2025-10-05T12:36:21+00:00\",\"dateModified\":\"2025-10-05T12:36:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/\"},\"wordCount\":2556,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/europe-3225257_1280.jpg\",\"keywords\":[\"Artificial Intelligence\",\"consumer data protection\",\"GDPR Compliance\",\"health-related data\",\"International transfers\"],\"articleSection\":[\"Data Protection Digest\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/\",\"name\":\"Data protection digest 17 Sep - 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/europe-3225257_1280.jpg\",\"datePublished\":\"2025-10-05T12:36:21+00:00\",\"dateModified\":\"2025-10-05T12:36:22+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: New Danish court ruling may change practice for GDPR compensations\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/europe-3225257_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/europe-3225257_1280.jpg\",\"width\":1280,\"height\":960,\"caption\":\"GDPR compensations\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 17 Sep &#8211; 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 17 Sep - 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: New Danish court ruling may change practice for GDPR compensations","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 17 Sep - 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: New Danish court ruling may change practice for GDPR compensations","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/","og_site_name":"TechGDPR","article_published_time":"2025-10-05T12:36:21+00:00","article_modified_time":"2025-10-05T12:36:22+00:00","og_image":[{"width":1280,"height":960,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 17 Sep &#8211; 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations","datePublished":"2025-10-05T12:36:21+00:00","dateModified":"2025-10-05T12:36:22+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/"},"wordCount":2556,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg","keywords":["Artificial Intelligence","consumer data protection","GDPR Compliance","health-related data","International transfers"],"articleSection":["Data Protection Digest","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/","name":"Data protection digest 17 Sep - 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg","datePublished":"2025-10-05T12:36:21+00:00","dateModified":"2025-10-05T12:36:22+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: New Danish court ruling may change practice for GDPR compensations","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/europe-3225257_1280.jpg","width":1280,"height":960,"caption":"GDPR compensations"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-05102025-new-danish-court-ruling-may-change-practice-for-gdpr-compensations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 17 Sep &#8211; 3 Oct 2025: New Danish court ruling may change practice for GDPR compensations"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=11201"}],"version-history":[{"count":9,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11201\/revisions"}],"predecessor-version":[{"id":11222,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11201\/revisions\/11222"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/11212"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=11201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=11201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=11201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}