{"id":8779,"date":"2024-07-22T12:16:09","date_gmt":"2024-07-22T10:16:09","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=8779"},"modified":"2024-07-22T12:16:10","modified_gmt":"2024-07-22T10:16:10","slug":"data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/","title":{"rendered":"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy"},"content":{"rendered":"\n<p><em>In this issue we highlight SOCMINT as a new standardised procedure, data processing in LLMs and supported AI systems, an updated standard data protection model, third-party tracking technologies in health and care, and much more.<\/em><\/p>\n\n\n\n<p><em><a href=\"#newslettersignup\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/a><\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>LLMs<\/strong> and personal data<\/h4>\n\n\n\n<p>The Hamburg Data Protection Commissioner discusses whether Large Language Models store personal data. It distinguishes between an LLM as an AI model, (eg, GPT-4), and as a component of an AI system, (eg, ChatGPT). The mere <a href=\"https:\/\/datenschutz-hamburg.de\/news\/hamburger-thesen-zum-personenbezug-in-large-language-models\">storage of an LLM does not constitute processing<\/a>. Thus, data subject rights cannot relate to the model itself. Claims for information, deletion or correction can rather relate to the input and output of an AI system of the responsible provider or operator.\u00a0<\/p>\n\n\n\n<p>To the extent that personal data is processed in an <a href=\"https:\/\/www.dataprotection.ie\/en\/dpc-guidance\/blogs\/AI-LLMs-and-Data-Protection\">LLM-supported AI system<\/a>, the processing operations must comply with the requirements of the GDPR. This applies in particular to the output of such a system. Similarly, any training that may violate data protection regulations does not affect the legality of using such a model in an AI system. See the <a href=\"https:\/\/datenschutz-hamburg.de\/fileadmin\/user_upload\/HmbBfDI\/Datenschutz\/Informationen\/240715_Diskussionspapier_HmbBfDI_KI_Modelle.pdf\">full discussion paper here<\/a>.<\/p>\n\n\n\n<p>The most recent clarifications by the French CNIL on the <a href=\"https:\/\/www.cnil.fr\/en\/how-deploy-generative-ai-cnil-provides-initial-clarifications\">deployment of Generative AI systems<\/a> and the official EU <a href=\"https:\/\/artificialintelligenceact.eu\/assessment\/eu-ai-act-compliance-checker\/#weglot_switcher\">AI Compliance Checker<\/a> might be useful for your organisation. The latter also recommends that you obtain expert legal advice before using AI solutions.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Privacy notice<\/h4>\n\n\n\n<p>The UK Information Commissioner encourages people to check how an app plans to use their personal information before they sign up. It is far too easy to just click \u201cagree\u201d when installing a new app. But signing up often involves handing over large amounts of your sensitive personal information, especially with apps that support our health. An organisation that values your privacy will make its privacy notice <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/07\/do-i-really-need-to-read-the-privacy-notice\/\">easy to understand<\/a> and set out how it will use your personal information, with whom it will be shared, what are the security measures, and whether your data will be deleted when you stop using it.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>CCTV<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-us.googleusercontent.com\/docsz\/AD_4nXf1-y9gUhoFPS6RAyl8wigQYV8W2gtW_82AVQ5e_a2y5ydYLfGcHCCGO2YCzAWrtv3XLvz2FQtnAe6iEGzFgdRLE7ebmEp8V3eQTtE2Vcm65YoF0T_tcJvjDsvzy4C47r5hAw2-vBWqO2h5OdLv8VB-wPA?key=DC1JcjJoIlkeI5ToqhHGvQ\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The operation of CCTV in gym facilities, on the one hand, should aim to ensure the protection of the facilities in question while on the other hand, it should respect the right of customers and employees to protect their privacy, reiterates the Cyprus data protection authority. CCTV can be permitted at a gym entrance\/exit, parking space, reception, (only the cashier), and general perimeter of the gym property.\u00a0<\/p>\n<\/div><\/div>\n\n\n\n<p>It is <a href=\"https:\/\/www.dataprotection.gov.cy\/DATAPROTECTION\/DATAPROTECTION.NSF\/All\/9CCCF618ED15F003C2258B5B003C45CB?OpenDocument\">not allowed in the areas where persons exercise<\/a>, kitchens, restrooms\/ changing rooms, and offices. Audio recording is not allowed under any circumstances. Video material must be accessible only from a device which is located within the premises of the gym and to which only the director and\/or an authorised person has access. Access to said material, from a personal device and on an ongoing basis, is not permitted.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More official guidance<\/h4>\n\n\n\n<p><strong>EU-US DPF:<\/strong> The EDPB has published the EU-US Data Privacy Framework <a href=\"https:\/\/www.edpb.europa.eu\/news\/news\/2024\/edpb-adopts-statement-dpas-role-ai-act-framework-eu-us-data-privacy-framework-faq_en\">FAQ <\/a>for European individuals and businesses: how to benefit from it, how to lodge a complaint and how this complaint should be handled by the EU and US authorities. It also includes what to do before transferring personal data to a DPF-certified company in the US, (data controllers or processors), and self-certification of US subsidiaries of EU\/EEA businesses.<\/p>\n\n\n\n<p><strong>DPIA:<\/strong> Industry professionals and interested parties are invited by the Latvian data protection authority DVI to share their thoughts and provide real-world examples of the Data Protection Impact Assessment. It is a procedure by which, through <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/aicinam-iesaistities-nida-vadliniju-izstrade\">risk inventory, analysis, and evaluation of prospective outcomes<\/a>, (identifying severity and likelihood), the organisation can identify potential dangers to natural persons that may occur from planned data processing. The DPIA also includes the identification of measures to prevent possible risks. The draft guidance can be read <a href=\"https:\/\/www.dvi.gov.lv\/lv\/media\/3051\/download?attachment\">here<\/a>, (in Latvian).<\/p>\n\n\n\n<p><strong>AI projects sandbox:<\/strong> The Danish data protection authority has selected two AI projects for examination in its sandbox project. One wants to develop an AI insurance assistant for structuring and summarising <a href=\"https:\/\/www.datatilsynet.dk\/presse-og-nyheder\/nyhedsarkiv\/2024\/jul\/to-ai-projekter-udvalgt-til-foerste-runde-af-den-regulatoriske-sandkasse\">accident claims<\/a>, (to determine the degree of injury more quickly than today). The other one is a public-private innovation to develop a solution that will ease the <a href=\"https:\/\/www.datatilsynet.dk\/presse-og-nyheder\/nyhedsarkiv\/2024\/jul\/to-ai-projekter-udvalgt-til-foerste-runde-af-den-regulatoriske-sandkasse\">documentation burden for employees in health and care<\/a>.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Social media monitoring<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"606\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/search-3539523_1280-1024x606.jpg\" alt=\"\" class=\"wp-image-8780 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/search-3539523_1280-1024x606.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/search-3539523_1280-300x178.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/search-3539523_1280-768x455.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/search-3539523_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>According to Privacy International, social media monitoring, or SOCMINT, is becoming <a href=\"https:\/\/privacyinternational.org\/long-read\/5337\/social-media-monitoring-uk-invisible-surveillance-tool-increasingly-deployed\">more common and standardised<\/a> but is still mostly uncontrolled and inconsistent. One of the most vivid examples is fraud investigations by the UK Department for Work and Pensions. Alongside covert surveillance tactics, the department\u2019s staff guide has an entire section on &#8220;<a href=\"https:\/\/www.gov.uk\/government\/publications\/fraud-investigations-staff-guide\">Open Source Instructions<\/a>\u201d on the use of publicly available information. <\/p>\n<\/div><\/div>\n\n\n\n<p>However, such invisible monitoring goes against or beyond individuals\u2019 reasonable expectations and their possibility to anticipate intrusive examination.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>GDPR in practice<\/strong><\/h4>\n\n\n\n<p>The Fundamental Rights Agency recently published the report &#8220;GDPR in practice &#8211; the experience of data protection authorities&#8221;. All the improvement areas directly or indirectly target the availability of <a href=\"https:\/\/fra.europa.eu\/et\/publication\/2024\/gdpr-experiences-data-protection-authorities\">human, financial and technical resources<\/a>. In particular,&nbsp; underfunded and understaffed authorities are obliged to prioritise complaints handling over other regulatory tasks that the GDPR has entrusted to them \u2013 such as promoting awareness and providing advice, undertaking their own investigations and external cooperation.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>SDM 3.0<\/strong><\/h4>\n\n\n\n<p>The German Data Protection Conference published the updated <a href=\"https:\/\/www.datenschutzkonferenz-online.de\/media\/ah\/SDM-Methode-V31.pdf\">Standard Data Protection Model<\/a> &#8211; a method for data protection advice and testing based on uniform objectives, Data Guidance reports. In particular, the model <a href=\"https:\/\/www.dataguidance.com\/news\/germany-dsk-releases-updated-standard-data-protection-0\">transfers the legal requirements into technical and organisational measures<\/a> required by the GDPR, which are detailed in the catalogue of reference measures. The SDM is aimed at both the supervisory authorities and those responsible for processing personal data.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>EHDS<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-us.googleusercontent.com\/docsz\/AD_4nXcIeS9exGV6hDA5adr6Tv9veXJoaK4wA9HLvWpp6vwSl-dySQ_whFE0jsppHVQzzPe4m40QmiqdsSxP9ESBDUtIQBcpM2plsSwi3dsucS43kgq0PxJgglpz2k1hLkDSq7IeOvbYRbwgrRYJdp3ZEpJDK2J9?key=DC1JcjJoIlkeI5ToqhHGvQ\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>In the next couple of years, patients, healthcare providers, and authorised researchers within the EU will start using the European Health Data Space, for which a DLA Piper legal blog provides the <a href=\"https:\/\/privacymatters.dlapiper.com\/2024\/07\/requirements-of-ehr-systems-under-the-european-health-data-space\">standards on the electronic health record system<\/a>. Interoperability and the logging component are two essential components of the software that make up this records system. Further requirements for conformity can be read in the <a href=\"https:\/\/privacymatters.dlapiper.com\/2024\/07\/requirements-of-ehr-systems-under-the-european-health-data-space\/\">original analysis<\/a>.\u00a0\u00a0<\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<p><strong>Dark patterns:<\/strong> The Canadian Privacy Commissioner with other counterparts conducted a review of over 1000 websites and apps, and found that nearly all had at least one deceptive design element that potentially violated <a href=\"https:\/\/techgdpr.com\/blog\/edpb-website-auditing-tool\/\">privacy requirements<\/a>. This includes <a href=\"https:\/\/www.priv.gc.ca\/media\/6299\/opc-gpen-2024-eng.pdf\">complex and confusing language, interface Interference, nagging, obstruction, and forced action<\/a>, (tricking users into disclosing more personal information to access a service than is necessary). When two or more deceptive design patterns are used together, they can become more effective.\u00a0\u00a0<\/p>\n\n\n\n<p><strong>HBNR: <\/strong>Starting in July, the amendments to the US Health Breach Notification Rule went into effect. These now underscore <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2024\/04\/ftc-finalizes-changes-health-breach-notification-rule\">health apps and similar technologies<\/a> not covered by Health Insurance Portability and Accountability. HBNR requires vendors of personal health records and related entities to notify individuals, the Federal Trade Commission, and, in some cases, the media of a breach of unsecured personally identifiable health data. It also requires third-party service providers to notify such vendors and related entities.\u00a0<\/p>\n\n\n\n<p><strong>Rhode Island<\/strong> became the <a href=\"https:\/\/fpf.org\/blog\/comprehensive-privacy-anchors-in-the-ocean-state\/#:~:text=On%20June%2025%2C%202024%2C%20Governor,enact%20a%20comprehensive%20privacy%20law.\">nineteenth US state<\/a> overall and the seventh state in 2024 to enact a comprehensive privacy law, The Future of Privacy Forum sums up. The law will take effect starting in 2026. The law includes familiar terminology and core obligations, such as controller\/processor responsibilities, rights of access, correction, deletion, portability, express consent for processing sensitive data, and disclosure requirements, but lacks data minimisation requirements or an obligation for controllers to recognize universal opt-out mechanisms.\u00a0<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_7822eb999c8661d78de3a1d2409c48ff\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Enforcement decisions<\/h4>\n\n\n\n<p><strong>Smart cameras in Turin: <\/strong>The Italian regulator Garante sent a request for information to the Municipality of Turin on a new <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/10035760\">video surveillance system that, reportedly, would also use AI<\/a>. It would allow municipal police to understand in real-time whether it is necessary to intervene in an emergency or for safety reasons. The Municipality was given <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/10035760\">15 days to clarify the advanced features<\/a> of the camera, and also send a copy of the technical documentation, and the purposes and legal basis of the processing of personal data.<\/p>\n\n\n\n<p><strong>Personal details on the intranet:<\/strong> The Finnish regulator ruled that a company, (a bus operator), did not have the right to publish 300 <a href=\"https:\/\/tietosuoja.fi\/-\/apulaistietosuojavaltuutettu-yrityksella-ei-ollut-oikeutta-julkaista-tyontekijoiden-henkilokohtaisia-puhelinnumeroita-intranetissa\">employees&#8217; personal phone numbers<\/a> on the intranet. The company argued it is important for drivers to communicate with each other while working. On their work phones they can only call predefined numbers, and sending text messages is blocked. The regulator argued that using a work number between drivers should be a prior communication method. In addition, employees&#8217; data may only be processed by persons whose job duties demand it, such as supervisors or HR.&nbsp;<\/p>\n\n\n\n<p><strong>Local government data: <\/strong>The UK Information Commissioner issued the London Borough of Hackney council with a reprimand following a cyberattack in 2020 that led to hackers gaining access to and encrypting 440,000 files. The data included residents&#8217; racial or ethnic origin, religious beliefs, sexual orientation, health, economic data, criminal offences, and other data including basic personal identifiers such as addresses. Hackers also deleted 10% of the council\u2019s backup. The <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2024\/07\/london-borough-of-hackney-reprimanded-following-cyber-attack\/\">systems were disrupted for many months<\/a> with, in some instances, services not being back to normal until 2022.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Drugstore visitors\u2019 tracking<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-us.googleusercontent.com\/docsz\/AD_4nXe8LYdpPctsOnLko_1jXjIzs6GJ1s0SHKfWnhPd6xa8f2RvMCg8ZFOPAE_88rnc9hNJ4384DGMTlEyHBp5vtwPp5jtjUZV3X33X4qEdy-s2ivcxzFiEOK29pqC2hUVXTdycW7kF7VUdd-mpDSlRzjZCAuYQ?key=DC1JcjJoIlkeI5ToqhHGvQ\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Dutch data protection authority, (AP), has imposed a fine of 600,000 euros on the parent company behind drugstore Kruidvat. The company, (AS Watson BV), <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/boete-van-600000-euro-voor-tracking-cookies-op-kruidvatnl\">tracked millions of visitors<\/a> of Kruidvat.nl, without their knowledge or permission, and was able to create personal profiles noting which pages they visited, which products they added to their shopping cart and bought, and which recommendations they clicked on.\u00a0 In the cookie banner on Kruidvat.nl, the boxes to agree to the placement of tracking software were checked by default. Visitors who wanted to refuse them had to go through several steps.\u00a0<\/p>\n<\/div><\/div>\n\n\n\n<p>More data on the use of third-party tracking technologies in the health and care sector can be read <a href=\"https:\/\/jamanetwork.com\/journals\/jamanetworkopen\/fullarticle\/2817444\">here<\/a>.\u00a0<\/p>\n\n\n\n<p><strong>Background checks:<\/strong> The province of British Columbia and the Privacy Commissioner of Canada have joined forces to investigate Certn Inc., a business that provides landlords with <a href=\"https:\/\/www.priv.gc.ca\/en\/opc-news\/news-and-announcements\/2024\/an_240711\/\">tenant screening services<\/a>. They will look at whether Certn complies with the requirements of both the federal Personal Information Protection and Electronic Documents Act and the Personal Information Protection Act of British Columbia, (where the company is based). In particular, it will look at whether the data it gathers, uses, and discloses for tenant screening is sufficiently accurate, complete, and up to date.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Data security<\/h4>\n\n\n\n<p><strong>Differential privacy: <\/strong>The latest US NIST cybersecurity insights discuss protecting trained models in Privacy-Preserving Federated Learning. The techniques must be combined with an <a href=\"https:\/\/www.nist.gov\/blogs\/cybersecurity-insights\/protecting-trained-models-privacy-preserving-federated-learning\">approach for output privacy,<\/a> which limits how much can be learned about individuals in the training data after the model has been trained.&nbsp;<\/p>\n\n\n\n<p>Differential privacy is the most robust known type of output privacy. To protect against privacy threats, techniques for differentially private machine learning incorporate random \u2018noise\u2019 into the model during training. The training data cannot be later recovered from the model because the random noise prevents the machine from remembering details from the training set.<\/p>\n\n\n\n<p><strong>Global IT outage: <\/strong>A Reuters analysis briefly explains the latest cyber outage when CrowdStrike\u2019s software update caused Microsoft Windows to crash. Companies such as CrowdStrike employ cloud-based solutions for virus scanning, early warning systems for possible cyberattacks, and barriers against hackers accessing company networks without authorisation. This time, a<a href=\"https:\/\/www.reuters.com\/technology\/what-caused-global-cyber-outage-2024-07-19\/\"> conflict appeared between CrowdStrike code and the Windows operating system&#8217;s code<\/a>, which is why certain PCs crashed even after they were rebooted.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Big Data<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-us.googleusercontent.com\/docsz\/AD_4nXf_S7-VUSjK71wJ63_FoI762PvLSGSP-KqjqucfH7j74S-E8yJWcj7l3nzYc_sHjfUsrCa8LlWGdOqxNBnJmIO0j24SHAONqP_qz_JKYexg7iKQwKE0jz53I0caW_6lHPh9reiHb-biGAn90gWDwG_shuqo?key=DC1JcjJoIlkeI5ToqhHGvQ\" alt=\"LLMs\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Chromebooks<\/strong>: The Danish data protection authority has assessed that 52 municipalities are now complying with its order from January to stop passing on the personal data of school children for unauthorised purposes to Google. There have been adaptations to the contract that ensure that personal data will only be processed following the instructions of the municipalities. The Danish regulator has also asked for the EDPB\u2019s opinion on a final assessment of the <a href=\"https:\/\/www.datatilsynet.dk\/presse-og-nyheder\/nyhedsarkiv\/2024\/jul\/chromebook-sagen-kommunerne-efterlever-datatilsynets-seneste-paabud-\">data processing chain in the municipalities&#8217; use of Google&#8217;s products<\/a>, (including for maintenance of infrastructure from the supplier&#8217;s side).<\/p>\n<\/div><\/div>\n\n\n\n<p><strong>Oracle reaches 115 mln privacy settlement <\/strong>in the US. The digital <a href=\"https:\/\/www.reuters.com\/legal\/oracle-reaches-115-mln-consumer-privacy-settlement-2024-07-19\/\">files of hundreds of millions of people<\/a> reportedly containing where they browsed online, where they did their banking, bought gas, dined out, shopped and used their credit cards were allegedly sold by Oracle directly to marketers. The company also agreed in future not to gather user-generated information from URLs of previously visited websites, or text that users enter in online forms other than on Oracle&#8217;s websites.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this issue we highlight SOCMINT as a new standardised procedure, data processing in LLMs and supported AI systems, an updated standard data protection model, third-party tracking technologies in health and care, and much more. Stay up to date! Sign up to receive our fortnightly digest via email. LLMs and personal data The Hamburg Data [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":8792,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[51,198,95,58,105,270],"class_list":["post-8779","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-artificial-intelligence","tag-cctv","tag-eu-us-data-transfer","tag-gdpr-compliance","tag-health-tech","tag-privacy-notice"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png",1280,867,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-300x203.png",300,203,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-768x520.png",640,433,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-1024x694.png",640,434,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png",1280,867,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png",1280,867,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-200x200.png",200,200,true]},"post_excerpt_stackable":"<p>In this issue we highlight SOCMINT as a new standardised procedure, data processing in LLMs and supported AI systems, an updated standard data protection model, third-party tracking technologies in health and care, and much more. Stay up to date! Sign up to receive our fortnightly digest via email. LLMs and personal data The Hamburg Data Protection Commissioner discusses whether Large Language Models store personal data. It distinguishes between an LLM as an AI model, (eg, GPT-4), and as a component of an AI system, (eg, ChatGPT). The mere storage of an LLM does not constitute processing. Thus, data subject rights&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png",1280,867,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-300x203.png",300,203,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-768x520.png",640,433,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-1024x694.png",640,434,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png",1280,867,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png",1280,867,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280-200x200.png",200,200,true]},"post_excerpt_stackable_v2":"<p>In this issue we highlight SOCMINT as a new standardised procedure, data processing in LLMs and supported AI systems, an updated standard data protection model, third-party tracking technologies in health and care, and much more. Stay up to date! Sign up to receive our fortnightly digest via email. LLMs and personal data The Hamburg Data Protection Commissioner discusses whether Large Language Models store personal data. It distinguishes between an LLM as an AI model, (eg, GPT-4), and as a component of an AI system, (eg, ChatGPT). The mere storage of an LLM does not constitute processing. Thus, data subject rights&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: LLMs and personal data, social media monitoring, differential privacy\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: LLMs and personal data, social media monitoring, differential privacy\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-22T10:16:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-07-22T10:16:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"867\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy\",\"datePublished\":\"2024-07-22T10:16:09+00:00\",\"dateModified\":\"2024-07-22T10:16:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/\"},\"wordCount\":2078,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/thank-you-6130334_1280.png\",\"keywords\":[\"Artificial Intelligence\",\"CCTV\",\"EU-US data transfer\",\"GDPR Compliance\",\"health tech\",\"privacy notice\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/\",\"name\":\"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/thank-you-6130334_1280.png\",\"datePublished\":\"2024-07-22T10:16:09+00:00\",\"dateModified\":\"2024-07-22T10:16:10+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: LLMs and personal data, social media monitoring, differential privacy\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/thank-you-6130334_1280.png\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/thank-you-6130334_1280.png\",\"width\":1280,\"height\":867,\"caption\":\"LLMs\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: LLMs and personal data, social media monitoring, differential privacy","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: LLMs and personal data, social media monitoring, differential privacy","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/","og_site_name":"TechGDPR","article_published_time":"2024-07-22T10:16:09+00:00","article_modified_time":"2024-07-22T10:16:10+00:00","og_image":[{"width":1280,"height":867,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png","type":"image\/png"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy","datePublished":"2024-07-22T10:16:09+00:00","dateModified":"2024-07-22T10:16:10+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/"},"wordCount":2078,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png","keywords":["Artificial Intelligence","CCTV","EU-US data transfer","GDPR Compliance","health tech","privacy notice"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/","name":"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png","datePublished":"2024-07-22T10:16:09+00:00","dateModified":"2024-07-22T10:16:10+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: LLMs and personal data, social media monitoring, differential privacy","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/07\/thank-you-6130334_1280.png","width":1280,"height":867,"caption":"LLMs"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-22072024-llms-and-personal-data-social-media-monitoring-differential-privacy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 5-19 Jul 2024: LLMs and personal data, social media monitoring, differential privacy"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8779","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=8779"}],"version-history":[{"count":12,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8779\/revisions"}],"predecessor-version":[{"id":8795,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8779\/revisions\/8795"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/8792"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=8779"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=8779"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=8779"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}