{"id":8258,"date":"2024-03-18T10:51:22","date_gmt":"2024-03-18T09:51:22","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=8258"},"modified":"2025-06-11T14:04:55","modified_gmt":"2025-06-11T12:04:55","slug":"data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/","title":{"rendered":"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors"},"content":{"rendered":"\n<p><em>Information systems, their security, and personal data gaps are the focus of our latest digest. Also requiring your attention are invalid consent in cookie walls, the \u2018pay or okay\u2019 subscription model, Open AI \u201cSora\u201d data practices, and the crackdown on mass data collectors<\/em><\/p>\n\n\n\n<p><em><a href=\"#newslettersignup\">Stay tuned! Sign up to receive our fortnightly digest via email.<\/a><\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Personal data gaps in information systems<\/h4>\n\n\n\n<p>The Spanish data protection agency AEPD examines the distinction between addressing security by focusing exclusively on information systems or from the perspective of the treatments carried out. Under the GDPR rules, a data controller must evaluate the risks to the rights and freedoms of natural persons whose data is being processed and apply measures to mitigate them. Therefore <a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/blog\/brechas-de-datos-personales-seguridad-enfocada-los-tratamientos\">security focused on processing activities is a broader concept than security focused exclusively on systems<\/a>. The scope of application of the GDPR is the processing of personal data, understood as processes with an ultimate and specific purpose, while the scope of application of other regulations, such as cybersecurity or artificial intelligence, is oriented to information and communications systems.&nbsp;<\/p>\n\n\n\n<p>An example that illustrates this difference is the case of access control operations in personal data processing &#8211; when third parties use compromised credentials to log into a service or application. Some controllers may incorrectly claim that a breach within the meaning of the GDPR has not occurred since, according to their opinion, the information systems have not been compromised. These controllers understand that the use of valid credentials to log in to the system has not led to a personal data breach in the processing as the system has functioned correctly.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u201cConsent or Pay\u201d initial guidance<\/h4>\n\n\n\n<p>Some businesses are considering giving people a choice between accessing online services without payment if they consent to their personal information being used for personalised advertising or, if they refuse this consent, having to pay to access that service. In principle, data protection law does not prohibit business models that involve \u201cconsent or pay\u201d, states the UK ICO. However, some types of access mechanisms aren\u2019t likely to comply with expectations in data protection law for consent to be \u2018freely given\u2019. The relevant context may include power imbalance, equivalence, appropriate fees, privacy by design, and information obligation:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cBeing upfront and honest with people about what happens to their personal information when they use the service is a good thing.\u201d <\/em><\/p>\n<cite><br><\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\">More official guidance<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:32% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/cloud-5469712_1280-1024x576.jpg\" alt=\"information systems\" class=\"wp-image-8259 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/cloud-5469712_1280-1024x576.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/cloud-5469712_1280-300x169.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/cloud-5469712_1280-768x432.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/cloud-5469712_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Data obtained as part of work duties: <\/strong>The Latvian regulator DVI explains the legality of data processing through <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-darba-pienakumu-ietvaros-ieguto-personas-datu-izmantosana-informacijas-sistemas\">information systems that hold personal information and to which access is authorised through employment<\/a>. We may directly or indirectly come into contact with other people&#8217;s data while carrying out our job, including customers, coworkers, and residents. <\/p>\n<\/div><\/div>\n\n\n\n<p>The organisation that grants its employees access to the systems must ensure, (if technically possible), that the employee accesses only the information necessary to perform the duties of their position. Personal interest or curiosity is no longer an adequate basis for looking into a database. In the case of a data processing infringement, the organisation should anticipate that, as the data controller, they would be the main responsible.&nbsp;<\/p>\n\n\n\n<p><strong>Automated decisions:<\/strong> The Spanish AEPD has updated guidance on the <a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/blog\/evaluacion-de-la-intervencion-humana-en-las-decisiones-automatizadas\">degree of human intervention in automated decisions<\/a>, (Art. 22 of the GDPR). Many automated decisions involve some degree of human intervention. However, to be considered as such, it has to be active and not just a symbolic gesture, that is, it has to have a certain degree of relevance and capacity. Evaluating whether human supervision is possible and effective involves evaluating both the system used and the treatment and its context. To carry out this evaluation systematically, it is recommended to objectively assess a person&#8217;s participation in the decision process. More details in the <a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/blog\/evaluacion-de-la-intervencion-humana-en-las-decisiones-automatizadas\">original publication (in Spanish<\/a>).\u00a0<\/p>\n\n\n\n<p><strong>Public affairs:<\/strong> As part of their activity, public affairs professionals, (public affairs or lobbying consulting firms, internal departments), collect personal data relating to individuals in sectors such as government, administrative, associative, parliamentary, media actors, etc. To help them comply with the GDPR, several associations representing <a href=\"https:\/\/mcusercontent.com\/e44fa53dc13e114d110ec2bd1\/files\/ae4fa623-e0a8-a3ff-7aef-f30ea28ed800\/Guide_RGPD_affaires_publiques_ACAP_AFCL_APAP_SCRP_.pdf\">business and public relations professionals have jointly developed a guide, drafted in consultation with the CNIL<\/a>, (in French).\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Legal&nbsp; processes<\/h4>\n\n\n\n<p><strong>EU AI Act: <\/strong>The Guardian analyses the practical implications of the upcoming regulations for customers and businesses. The act <a href=\"https:\/\/iapp.org\/resources\/article\/eu-ai-act-101\/\">will soon become law<\/a> and go into effect gradually over the following three years. <a href=\"https:\/\/www.theguardian.com\/technology\/2024\/mar\/14\/what-will-eu-proposed-regulation-ai-mean-consumers\">Customers will feel more certain that the AI technologies are configured for safe use<\/a> as a result. Similar to how the GDPR role model worked, the legislation will likewise have an impact outside the EU. However, the EU&#8217;s proposed cap on computing power used to train AI models is far lower than equivalent laws in the US. Consequently, European companies could even decide to relocate west to get around EU regulations, warn some tech businesses.<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/doctor-6029079_1280-1-1024x682.png\" alt=\"\" class=\"wp-image-8261 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/doctor-6029079_1280-1-1024x682.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/doctor-6029079_1280-1-300x200.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/doctor-6029079_1280-1-768x512.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/doctor-6029079_1280-1.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>European Health Data Space:<\/strong> EU legislators have struck a provisional agreement on the exchange and access of health data at the union level. Currently, the level of digitalisation of health data in the EU varies from one member state to another. The proposed regulation requires all electronic health record systems to comply with the specifications of the European electronic health record exchange format, ensuring that they are interoperable at the EU level. <\/p>\n<\/div><\/div>\n\n\n\n<p><a href=\"https:\/\/www.consilium.europa.eu\/en\/press\/press-releases\/2024\/03\/15\/european-health-data-space-council-and-parliament-strike-provisional-deal\/\">Patients still will have the right to opt-out from primary and secondary use of their data or restrict access to it with some exceptions<\/a>, (eg, scientific research, public interest, vital interests).&nbsp;<\/p>\n\n\n\n<p><strong>IAB Europe:<\/strong> The CJEU holds, as argued by the Belgian data protection regulator, that a structured character string capturing internet users&#8217; preferences such as <a href=\"https:\/\/www.dataprotectionauthority.be\/citizen\/iab-europe-case-the-cjeu-answers-the-questions-referred-for-a-preliminary-ruling\">IAB Europe&#8217;s TC string can be considered personal data<\/a>. TC String constitutes personal data, in particular, because its purpose is to link advertising preferences to a specific individual. As a sectoral organisation which standardises and prescribes the method for capturing and transmitting user preferences, IAB Europe can be indeed considered a (joint) controller concerning the processing carried out following this method.<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_3e821be7c2816bf767f3f39a7d1a5cd3\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Data erasure request<\/h4>\n\n\n\n<p>Another ruling by the CJEU states that the supervisory authority of a Member State may order the <a href=\"https:\/\/curia.europa.eu\/jcms\/upload\/docs\/application\/pdf\/2024-03\/cp240048en.pdf\">erasure of unlawfully processed data<\/a> even in the absence of a prior request by the data subject. Such erasure may cover data collected from that person and data originating from another source if such a measure is necessary to fulfil its responsibility for ensuring that the GDPR is fully enforced. The case relates to the provision of financial support to persons who have been made vulnerable by the COVID-19 pandemic, (in Hungary), and the data breaches committed by a local administration affecting eligible persons who had not applied for the support.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Bank security failed<\/h4>\n\n\n\n<p>The Italian data protection authority Garante fined UniCredit 2.8 million euros and the company responsible for carrying out its security tests 800,000 euros. The violation had occurred due to <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/9991101\">a massive cyber attack on the mobile banking portal<\/a>. The attack caused the illicit acquisition of the name, surname, and other identifiers of approximately 778,000 customers and former customers and, for over 6,800 of the customers, it had also led to the disclosure of the portal access PIN. The data was made available in the HTTP response provided by the bank&#8217;s systems to the browser of anyone who tried to access, even unsuccessfully, the mobile banking portal.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More enforcement decisions<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brick-wall-146753_1280-1024x1024.png\" alt=\"\" class=\"wp-image-8266 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brick-wall-146753_1280-1024x1024.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brick-wall-146753_1280-300x300.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brick-wall-146753_1280-150x150.png 150w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brick-wall-146753_1280-768x768.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brick-wall-146753_1280-200x200.png 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brick-wall-146753_1280.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Invalid consent in cookie walls:<\/strong> The Danish data protection authority Datatilsynet ruled the use of cookie walls on Berlingske.dk must take place within the framework of the data protection rules. Berlingske&#8217;s specific approach is <a href=\"https:\/\/www.datatilsynet.dk\/presse-og-nyheder\/nyhedsarkiv\/2024\/mar\/ugyldigt-samtykke-i-cookie-walls-paa-berlingskedk\">to greet users with a cookie wall when they try to access embedded content<\/a>, (eg, video players or blog posts). This means that the content is unavailable unless the user accepts the processing of their data for statistical and marketing purposes through the use of cookies.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p><strong>European Commission\u2019s use of&nbsp; Microsoft 365: <\/strong>Following its investigation, the EDPS has found that the <a href=\"https:\/\/www.edps.europa.eu\/press-publications\/press-news\/news_en?page=0#news_13335\">European Commission has infringed several key data protection rules when using Microsoft 365.<\/a>&nbsp; The Commission has failed to provide appropriate safeguards to ensure that personal data transferred outside the EU\/EEA are afforded an essentially equivalent level of protection. Furthermore, in its contract with Microsoft, the Commission did not sufficiently specify what types of personal data are to be collected and for which explicit and specified purposes when using Microsoft 365. More <a href=\"https:\/\/www.edps.europa.eu\/system\/files\/2024-03\/EDPS-2024-05-European-Commission_s-use-of-M365-infringes-data-protection-rules-for-EU-institutions-and-bodies_EN.pdf\">details of the case can be read here<\/a>.&nbsp;<\/p>\n\n\n\n<p><strong>Commercial prospecting:<\/strong> The French CNIL fined Foriou company 310,000 euros for <a href=\"https:\/\/www.cnil.fr\/fr\/prospection-commerciale-sanction-de-310-000-euros-lencontre-de-la-societe-foriou\">using data provided by data brokers for commercial prospecting purposes<\/a>. It conducts telephone canvassing campaigns to promote the loyalty programs and cards it sells. The misleading appearance of the collection forms implemented by the brokers at the origin of the collection did not make it possible to obtain valid consent from the persons concerned. The size of this fine, which represents approximately 1% of the company&#8217;s turnover, was decided in light of the seriousness of the breach.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Information security audit<\/h4>\n\n\n\n<p>Moorfields Eye Hospital NHS Foundation Trust has undergone a consensual data protection audit conducted by the UK\u2019s ICO. The scope areas were determined following a risk-based analysis of the trust\u2019s processing of personal data. The suggestions for improvement included some tips on information security and data sharing,\u00a0and included the following advice:<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:27% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/audit-2823174_1280-1024x1024.png\" alt=\"Information systems\" class=\"wp-image-8268 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/audit-2823174_1280-1024x1024.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/audit-2823174_1280-300x300.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/audit-2823174_1280-150x150.png 150w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/audit-2823174_1280-768x768.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/audit-2823174_1280-200x200.png 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/audit-2823174_1280.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The permanent roles which make up the Information Security function should be filled quickly to ensure that operational responsibility is clearly in place.<\/li>\n\n\n\n<li>A template letter should be in place to notify data subjects of a data breach which includes all appropriate information including details of the DPO, a description of the likely consequences of the breach and the measures which have been taken.<\/li>\n\n\n\n<li>Appropriate reviewing processes should be in place for all data-sharing agreements, which include review schedules and review logs.<\/li>\n\n\n\n<li>The trust should have measures in place to ensure that relevant staff receive appropriate training, and ensure this is periodically refreshed.<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n\n<p>Among best practices, the ICO recognised that the trust tests their physical security on-site, with police officers being shown around and then returning at a later date in plain clothes to assess the security, for example by seeing if they can get into secure areas or move around unchallenged without appropriate ID.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">When user login data is made public<\/h4>\n\n\n\n<p>The Lithuanian data protection authority VDAI reminds us that upon receiving information about potentially leaked login names and passwords, an organisation, (the data controller), should conduct a preliminary investigation and determine whether there has been a <a href=\"https:\/\/vdai.lrv.lt\/lt\/naujienos\/vdai-pataria-paviesinti-vartotoju-prisijungimo-duomenys-kaip-elgtis\/\">violation of the confidentiality, integrity or availability of personal data<\/a>. For example, it should establish whether the personal data processed in the organisation&#8217;s information systems has been compromised.&nbsp;&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>If the processed personal data has not been accessed by unauthorised persons, the data controller still must assess the risks, prevent possible negative consequences, and let users know what action they can take in this situation, (eg, block user accounts whose login data matches the leaked data, generate new temporary passwords and send them to affected data subjects, activate two-factor authentication, etc.)\u00a0<\/li>\n<\/ol>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\">\n<li>If the processed personal data has been accessed by unauthorised persons, (eg, illegal logins to user accounts are detected or it is not possible to unequivocally determine that there were no such logins, illegal actions on accounts are detected, etc.),&nbsp; the organisation must conduct a full investigation, take immediate measures, notify the data subjects, and report to the regulator within 72 hours of becoming aware of the breach.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>As a <a href=\"https:\/\/vdai.lrv.lt\/lt\/naujienos\/vdai-pataria-paviesinti-vartotoju-prisijungimo-duomenys-kaip-elgtis\/\">general precaution,<\/a> VDAI also advises individuals to take the following precautions in\u00a0similar situations:<br><\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:17% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"682\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/school-4615186_1280-682x1024.jpg\" alt=\"information systems\" class=\"wp-image-8276 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/school-4615186_1280-682x1024.jpg 682w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/school-4615186_1280-200x300.jpg 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/school-4615186_1280-768x1152.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/school-4615186_1280.jpg 853w\" sizes=\"(max-width: 682px) 100vw, 682px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Change your password to a new and unique one. If you have used the same password on other systems, please change them as well.<\/li>\n\n\n\n<li>It should consist of at least 12 characters: letters, numbers, at least one capital letter and a special character.<\/li>\n\n\n\n<li>Do not store your passwords in browsers.<\/li>\n\n\n\n<li>Watch for news or announcements from your service provider, or authorities.<\/li>\n\n\n\n<li>Install and regularly update antivirus software on your devices.<\/li>\n\n\n\n<li>&nbsp;If you notice any suspicious activity in your account or related systems, notify your service provider immediately.<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Big Tech<\/h4>\n\n\n\n<p><strong>OpenAI \u201cSora\u201d: <\/strong>Italian regulator Garante has opened an investigation against OpenAI that in recent weeks has announced the launch of a new <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/9991867\">AI model, \u2018Sora\u2019, which, according to the announcement, can create dynamic, realistic and imaginative video sequences from short text<\/a> instructions. OpenAI will also have to clarify several issues:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>how the algorithm is trained;&nbsp;<\/li>\n\n\n\n<li>what data is collected and processed to train the algorithm, especially whether it is personal data;&nbsp;<\/li>\n\n\n\n<li>whether particular categories of data, (religious or philosophical beliefs, political opinions, genetic data, health, sexual life), are collected, and&nbsp;<\/li>\n\n\n\n<li>which sources are used.<\/li>\n<\/ul>\n\n\n\n<p><strong>Crackdown on mass data collectors:<\/strong> Several recent FTC enforcement actions reflect a heightened focus on <a href=\"https:\/\/www.ftc.gov\/policy\/advocacy-research\/tech-at-ftc\/2024\/03\/ftc-cracks-down-mass-data-collectors-closer-look-avast-x-mode-inmarket\">pervasive extraction and mishandling of consumers\u2019 sensitive personal data<\/a>, states an FTC blog post. Taken together, browsing and location data paint an intimate picture of a person\u2019s life, including their religious affiliations, health and medical conditions, financial status, and sexual orientation. None of the underlying datasets at issue in the FTC\u2019s proposed complaints, (against Avast, X-Mode, or InMarket), are alleged to have contained people\u2019s names, social security numbers, or other traditional standalone elements of personally identifiable information.&nbsp;<\/p>\n\n\n\n<p>What makes the underlying data sensitive springs from the insights they reveal, (eg, through proprietary algorithms), and the ease with which those insights can be attributed to particular people. People also have no way to object to how their data is collected, retained, used, and disclosed when these practices are hidden from them. Moreover, any safeguards used to maintain people\u2019s privacy are often outstripped by companies\u2019 incentives and abilities to match data to particular people.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Information systems, their security, and personal data gaps are the focus of our latest digest. Also requiring your attention are invalid consent in cookie walls, the \u2018pay or okay\u2019 subscription model, Open AI \u201cSora\u201d data practices, and the crackdown on mass data collectors Stay tuned! Sign up to receive our fortnightly digest via email. Personal [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":8297,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[51,129,100,179,98,89,58,258],"class_list":["post-8258","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-artificial-intelligence","tag-consumer-data-protection","tag-cookies","tag-data-brokers","tag-direct-marketing","tag-dpo","tag-gdpr-compliance","tag-health-related-data"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>Information systems, their security, and personal data gaps are the focus of our latest digest. Also requiring your attention are invalid consent in cookie walls, the \u2018pay or okay\u2019 subscription model, Open AI \u201cSora\u201d data practices, and the crackdown on mass data collectors Stay tuned! Sign up to receive our fortnightly digest via email. Personal data gaps in information systems The Spanish data protection agency AEPD examines the distinction between addressing security by focusing exclusively on information systems or from the perspective of the treatments carried out. Under the GDPR rules, a data controller must evaluate the risks to the&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>Information systems, their security, and personal data gaps are the focus of our latest digest. Also requiring your attention are invalid consent in cookie walls, the \u2018pay or okay\u2019 subscription model, Open AI \u201cSora\u201d data practices, and the crackdown on mass data collectors Stay tuned! Sign up to receive our fortnightly digest via email. Personal data gaps in information systems The Spanish data protection agency AEPD examines the distinction between addressing security by focusing exclusively on information systems or from the perspective of the treatments carried out. Under the GDPR rules, a data controller must evaluate the risks to the&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors - TechGDPR<\/title>\n<meta name=\"description\" content=\"echGDPR\u2019s review of the most important data privacy stories: personal data gaps in information systems, TC string, mass data collectors\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"echGDPR\u2019s review of the most important data privacy stories: personal data gaps in information systems, TC string, mass data collectors\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-18T09:51:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-11T12:04:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors\",\"datePublished\":\"2024-03-18T09:51:22+00:00\",\"dateModified\":\"2025-06-11T12:04:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/\"},\"wordCount\":2292,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/earth-5216964_1280.jpg\",\"keywords\":[\"Artificial Intelligence\",\"consumer data protection\",\"cookies\",\"data brokers\",\"direct marketing\",\"dpo\",\"GDPR Compliance\",\"health-related data\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/\",\"name\":\"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/earth-5216964_1280.jpg\",\"datePublished\":\"2024-03-18T09:51:22+00:00\",\"dateModified\":\"2025-06-11T12:04:55+00:00\",\"description\":\"echGDPR\u2019s review of the most important data privacy stories: personal data gaps in information systems, TC string, mass data collectors\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/earth-5216964_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/earth-5216964_1280.jpg\",\"width\":1280,\"height\":853},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors - TechGDPR","description":"echGDPR\u2019s review of the most important data privacy stories: personal data gaps in information systems, TC string, mass data collectors","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors - TechGDPR","og_description":"echGDPR\u2019s review of the most important data privacy stories: personal data gaps in information systems, TC string, mass data collectors","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/","og_site_name":"TechGDPR","article_published_time":"2024-03-18T09:51:22+00:00","article_modified_time":"2025-06-11T12:04:55+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors","datePublished":"2024-03-18T09:51:22+00:00","dateModified":"2025-06-11T12:04:55+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/"},"wordCount":2292,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg","keywords":["Artificial Intelligence","consumer data protection","cookies","data brokers","direct marketing","dpo","GDPR Compliance","health-related data"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/","name":"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg","datePublished":"2024-03-18T09:51:22+00:00","dateModified":"2025-06-11T12:04:55+00:00","description":"echGDPR\u2019s review of the most important data privacy stories: personal data gaps in information systems, TC string, mass data collectors","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/earth-5216964_1280.jpg","width":1280,"height":853},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-18032024-personal-data-gaps-in-information-systems-tc-string-mass-data-collectors\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 3-17 Mar 2024: Personal data gaps in information systems, TC string, mass data collectors"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=8258"}],"version-history":[{"count":33,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8258\/revisions"}],"predecessor-version":[{"id":10735,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8258\/revisions\/10735"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/8297"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=8258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=8258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=8258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}