{"id":9541,"date":"2024-11-02T12:05:22","date_gmt":"2024-11-02T11:05:22","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=9541"},"modified":"2025-07-08T13:55:31","modified_gmt":"2025-07-08T11:55:31","slug":"data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/","title":{"rendered":"Data protection digest 17 &#8211; 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\"><strong>Non-for-Profit<\/strong><\/h4>\n\n\n\n<p>Updated privacy guidance for not-for-profit has been released by the Office of the Australian Information Commissioner. It includes a discussion on what to consider when engaging third-party providers, such as for fundraising, or software vendors.\u00a0For instance, when entering into arrangements with third parties, your non-for-profit should take reasonable steps to ensure that the third party\u2019s privacy practices <a href=\"https:\/\/www.oaic.gov.au\/news\/media-centre\/draft-media-release-updated-nfpcharities-guidance\">meet the expectations of both your non-for-profit and the wider community<\/a>, (donors, volunteers, and people who engage with the sector as clients and staff). It is important to read the terms of your agreement carefully, conduct periodic reviews, and ensure the <a href=\"https:\/\/www.oaic.gov.au\/privacy\/privacy-guidance-for-organisations-and-government-agencies\/organisations\/privacy-for-not-for-profits,-including-charities\">third party deletes any personal information<\/a> at the end of the contract term.\u00a0<\/p>\n\n\n\n<p><a href=\"#newslettersignup\"><em>Stay up to date! Sign on to receive our fortnightly digest via email.<\/em><\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Consent management in Germany<\/strong><\/h4>\n\n\n\n<p>On 17 October the Bundestag approved the regulation that introduces <a href=\"https:\/\/www.bundestag.de\/dokumente\/textarchiv\/2024\/kw42-de-telekommunikation-1023844\">recognised consent management services<\/a> to manage decisions made by end users regarding consent or non-consent to a digital service provider, thus relieving them of some of the burden, (of individual decisions that have to be made with cookie consent banners). The integration of recognised consent management services by providers of digital services is voluntary. It now has to be approved by the government and officially published to come into effect. The original regulation, (in German), can be read <a href=\"https:\/\/dserver.bundestag.de\/btd\/20\/134\/2013418.pdf\">here<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Clinical research organisations (CROs)<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/laptop-2559958_1280-1024x682.jpg\" alt=\"non-for-profit\" class=\"wp-image-9542 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/laptop-2559958_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/laptop-2559958_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/laptop-2559958_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/laptop-2559958_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The French CNIL has approved a Code of Conduct intended for clinical research organisations and other service providers ,(CROs), who act as processors on behalf of sponsors. It brings an operational dimension to the requirements of the GDPR. It is supported by the non-for-profit European Clinical Research Federation (EUCROF) and is <a href=\"https:\/\/www.cnil.fr\/fr\/liste-codes-de-conduite-approuves-par-la-cnil\">mandatory for those who adhere to it<\/a>.\u00a0<\/p>\n<\/div><\/div>\n\n\n\n<p>Among the <a href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-17102024-knowing-your-processors-and-sub-processors-automated-driving-election-technologies\/\">services<\/a> offered by CROs that may be covered by the code are the design of the protocol, the selection and contracting with the investigator centers, the collection and hosting of data, their analysis and the production of reports, or archiving or technical support services.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Other legal updates<\/h4>\n\n\n\n<p><strong>NIS2 directive takes effect: <\/strong>New regulations to improve the cybersecurity of the EU&#8217;s vital networks and entities, (\u201cNIS2\u201d), should have been <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_24_5342\">incorporated into national legislation by the October 17<\/a> deadline. According to a DLA Piper analysis, although some Member States such as Croatia, Hungary and Belgium have transposed the directive into national legislation, the <a href=\"https:\/\/privacymatters.dlapiper.com\/2024\/10\/eu-nis2-member-state-implementation-deadline-has-arrived\/\">majority of EU countries do not yet have<\/a> the relevant implementing legislation and necessary guidelines for organisations in place.&nbsp;<\/p>\n\n\n\n<p><strong>Sanction lists: <\/strong>The Swedish IMY has drawn up new regulations that make it permissible for certain companies to handle personal data about violations of the law without seeking permission from the regulator when, among other things, <a href=\"https:\/\/www.imy.se\/nyheter\/nya-foreskrifter-forenklar-for-foretag-att-genomfora-kontroller-mot-sanktionslistor\/\">checking their customers against various sanction lists<\/a>. In particular, companies that operate in the financial sector as well as in the security and defence market may need to check their customers, suppliers and employees, to comply with international export restrictions, and against money laundering and the financing of terrorism.\u00a0\u00a0<\/p>\n\n\n\n<p><strong>Lawful collection of criminal records: <\/strong>The Danish data protection authority investigated Parken Services A\/S&#8217; procedures for obtaining information in the recruitment process. In particular, it obtains copies of passports and criminal records from applicants. The regulator found this processing lawful taking into account the special circumstances that apply to Parken Services A\/S as an employer, including the very large number of people employed by the company, and the very special risk profile associated with a company servicing <a href=\"https:\/\/www.datatilsynet.dk\/presse-og-nyheder\/nyhedsarkiv\/2024\/okt\/parken-services-as%e2%80%99-behandling-af-personoplysninger-ved-rekruttering\">large sporting and entertainment events, especially concerning terrorism and crime<\/a>.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Worker transfers data to private account without permission<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcSUMYKq5L73sC-Me05ToxU8j9GsaOE9VM7Mzd76AKHTnwold27m947vEQRJlAXCATWpgRrTEnP4e0aMIbJSpmc25SeaHrfcqES5esz0IfMuN1BXQVeDT8BPbkVFB4pQ6NAIFTEFzFlIk8urhZKz0t1r03r?key=wVHWyLYM0mK5PugMEu5X9Q\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>An Ius Laboris law blog post analyses the recent case in the Netherlands where an employee was dismissed because he <a href=\"https:\/\/iuslaboris.com\/insights\/what-happens-when-an-employee-transfers-data-without-permission\/\">sent 791 documents from his employer\u2019s server to his personal Dropbox<\/a> account, shortly after he was told that his fixed-term employment contract would not be extended. The employer had an IT policy that stated that employees could not make copies of the employer\u2019s data or store information from the employer in personal locations. <\/p>\n<\/div><\/div>\n\n\n\n<p>Additionally, the employer had recently sent an email to all employees reminding them that they were\u202fnot\u202fallowed to take any documents or property from the employer with them at the end of their contract. Read more discoveries of the case in the <a href=\"https:\/\/iuslaboris.com\/insights\/what-happens-when-an-employee-transfers-data-without-permission\/\">original publication<\/a>.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Commercially available AI<\/strong><\/h4>\n\n\n\n<p>The Office of the Australian Information Commissioner has also issued new AI guidance. AI products should not be used <a href=\"https:\/\/www.oaic.gov.au\/privacy\/privacy-guidance-for-organisations-and-government-agencies\/guidance-on-privacy-and-the-use-of-commercially-available-ai-products\">simply because they are available<\/a>, it says. Robust privacy governance and safeguards are essential for businesses to gain any advantage from AI and build trust and confidence in the community. Similarly, during AI model training, it must be carefully considered whether this will involve the collection, storage, use or disclosure of personal information, either <a href=\"https:\/\/www.oaic.gov.au\/news\/blog\/can-personal-information-be-used-to-develop-or-train-a-generative-ai-model\">by design or through an overly broad collection of data for training<\/a>. Do this early in the process to help mitigate any privacy risks. Personal information is a broad category, and the risk of data re-identification needs to be considered.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More official guidance<\/h4>\n\n\n\n<p><strong>Mobile apps design: <\/strong>Apps often ask for permissions that they don&#8217;t need to function properly, (geolocation, contacts, camera or mic). It is recommended to accept only those strictly necessary for the function of the service. Apps also collect data about your behaviour, such as which web pages you visit, how long you spend in an app, or which features you use most often. This information <a href=\"https:\/\/www.apda.ad\/noticia\/protegeix-la-teva-privadesa-a-les-aplicacions-mobils\">may be used for ad personalisation<\/a>, but you can limit or disable it in the privacy settings of your account. It is also recommended to use <a href=\"https:\/\/www.apda.ad\/noticia\/protegeix-la-teva-privadesa-a-les-aplicacions-mobils\">temporary accounts or alternate email addresses that are not linked to sensitive data<\/a>.\u00a0<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfPkBgFZXeHyNLVhQBVBO0Hn5wyv8MgmFfZ2g8zImOCmyl_2zZW0M-6SOoOwo4pz-mHUcutsC_uPvqdQYPyIngWOjpBIfzq4RJ0KV5JXG5zY16odrkGRGxrCNHIoLGjn4Af_sjN80pR88ewTn08fFuYuuM6?key=wVHWyLYM0mK5PugMEu5X9Q\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Learning environments: <\/strong>The Estonian regulator emphasized the obligation of educational institutions and their learning environments to maintain the appropriate technical and organisational measures. This includes reviewing the documents and personal data entered into online environments and their retention periods, creating a system for monitoring data retention periods and deleting data at the end of a period, and ensuring that employees are informed of data protection conditions.\u00a0<\/p>\n<\/div><\/div>\n\n\n\n<p>It is also important that the data can be partially deleted so that it does not prevent the further processing of other data, (eg, <a href=\"https:\/\/www.aki.ee\/uudised\/soovitused-koolidele-ja-oppekorralduskeskkondadele-isikuandmete-sailitamise-kohta\">making the data non-personal<\/a> and storing it for archiving, scientific and historical research or statistical purposes).\u00a0<\/p>\n\n\n\n<p><strong>Work emails backup: <\/strong>The Italian Garante fined a company 80,000 euros for carrying out <a href=\"https:\/\/www.garanteprivacy.it\/home\/docweb\/-\/docweb-display\/docweb\/10066116\">backups during the employment relationship<\/a>. The complaint was filed by a commercial agent who realised that the company, during their collaboration, used software to back up emails, preserving both their contents and access logs to the emails and the company management system. The information collected was then used by the company in litigation. This also allowed the company to reconstruct the collaborator&#8217;s activity, thus incurring a form of control prohibited by the workers&#8217; statute.<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_5b1a064deaeb6107c33f9c491a28ff45\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email    <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data, and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">More enforcement decisions<\/h4>\n\n\n\n<p><strong>LinkedIn fine:<\/strong> The Irish Data Protection Commission fined LinkedIn Ireland 310 million euros. The inquiry examined LinkedIn\u2019s processing of personal data for behavioural analysis and targeted advertising of users who have created LinkedIn profiles. LinkedIn <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/press-releases\/irish-data-protection-commission-fines-linkedin-ireland-eu310-million\">did not validly rely on consent<\/a> to process third-party data of its members for behavioural analysis and targeted advertising. <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/press-releases\/irish-data-protection-commission-fines-linkedin-ireland-eu310-million\">Similar validity issues applied to the legitimate interest and contractual<\/a> processing of first-party personal data.\u00a0<\/p>\n\n\n\n<p><strong>Health data breach: <\/strong>The New York Attorney General <a href=\"https:\/\/urldefense.com\/v3\/__https:\/links-1.govdelivery.com\/CL0\/https:*2F*2Fag.ny.gov*2Fsites*2Fdefault*2Ffiles*2Fsettlements-agreements*2Faent-final-aod-fully-executed.pdf\/1\/01000192d91d22b0-7dd89d9d-f202-4bbd-b3c3-17f05ec89ea7-000000\/FxJ0ZW4o7gU73uaNLCuYbaKlm7oyWp6YrNfSYre7FHg=377__;JSUlJSUlJQ!!Ke5ujdWW74OM!9irw9YLOR2rAVD2KJ9xkok0A7hpb3hVA-EdXWbkuL6xHRvBR1hNG2DdmQCDs8-Zdr1XZRnnYVdbudtFZjGx7PFDLARfebkWUMTRZwASJSDix$\">secured 2.25 million dollars from a health care provider AENT<\/a> for failing to protect the medical data of 200,000 New York patients. AENT <a href=\"https:\/\/ag.ny.gov\/press-release\/2024\/attorney-general-james-secures-225-million-capital-region-health-care-provider#:~:text=October%2029%2C%202024,medical%20data%20of%20New%20Yorkers.\">failed to adequately monitor the third-party vendors responsible for their cybersecurity<\/a> functions. As a result, those vendors did not install critical security software updates promptly, adequately log and monitor network activity, properly encrypt consumers\u2019 private information before and after any attacks, utilise multi-factor authentication for all remote access, or otherwise maintain a reasonable information security program. Finally, AENT\u2019s data storage devices continued to host unprotected private information months after two ransomware incidents occurred. Read more <a href=\"https:\/\/krebsonsecurity.com\/2024\/10\/change-healthcare-breach-hits-100m-americans\/\">insights on massive health data breaches in the US here<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:23% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeE6Ib8tIHZi5EQC1k39mK93ugq2xbmEGzg5HLHf6MTxBHmWcxpW87cTa8tpocZddvDYAX7xyr8-m1cx3v8RN97EVjAgiDLVjDPtS01C3lyGJN7pc-X5wx8QBfdplsHluuHQfTXfuW5IGdGWVlxcNWOTBU?key=wVHWyLYM0mK5PugMEu5X9Q\" alt=\"\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Pinterest:<\/strong> Privacy advocacy group NOYB filed a complaint against the social media platform Pinterest, including its visual mood board used for finding ideas and inspiration. Advertisers, on the other hand, use the platform to push their products to consumers. Pinterest\u2019s business model is also based on personalised advertising and the associated user tracking. The platform allegedly uses people\u2019s data without asking for their consent. <\/p>\n<\/div><\/div>\n\n\n\n<p>Pinterest claims to have a legitimate interest and <a href=\"https:\/\/noyb.eu\/en\/pinterest-pins-users-data-down-without-consent\">enables tracking by default<\/a>.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Data security<\/strong><\/h4>\n\n\n\n<p><strong>Ransomware<\/strong>: In 2023, there were more ransomware attacks in the Netherlands than previously. The AP counted at least 178 successful attacks. The number of affected organisations runs into hundreds. Millions of people&#8217;s data were affected, from emails and phone numbers to copies of passports, bank account numbers, and passwords. The AP notes that while cybercriminals sometimes target one specific company in a certain sector, they also <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/ap-meer-ransomware-aanvallen-dan-tot-nu-toe-bekend\">regularly attack IT suppliers that manage data<\/a> on behalf of a range of companies from all sectors.\u00a0<\/p>\n\n\n\n<p><strong>Google Analytics: <\/strong>The Saxony Data Protection Commissioner discovered the illegal use of Google Analytics on 2,300 out of the 30,000 websites it examined, (compliance improved significantly throughout the inspections). Data was collected without the visitors having previously consented to the setting of analytics cookies and\/or the establishment of server connections to Google Analytics. A <a href=\"https:\/\/www.datenschutz.sachsen.de\/kontrolle-der-sdtb-sorgt-fuer-verbesserung-des-datenschutzes-auf-ueber-1-500-saechsischen-websites-7308.html\">significant number of consent banners often did not do what the settings promised<\/a> users. Services were executed and cookies were set even though the settings indicated &#8220;off&#8221;. Many of the website administrators were unaware of this.\u00a0<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"791\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/programming-7649719_1280-1024x791.jpg\" alt=\"\" class=\"wp-image-9549 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/programming-7649719_1280-1024x791.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/programming-7649719_1280-300x232.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/programming-7649719_1280-768x593.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/programming-7649719_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Mobile surveillance:<\/strong> The Krebs-on-Security law blog reports on a recent ad data surveillance case. The Delaware-based Atlas Data Privacy Corp. invoked <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2024\/10\/2024.10.18_Babel_Street_Compl_w_Summons-Case_Info_-_4874-8628-4017_-_1__1_.pdf\">a lawsuit<\/a> against Babel Street, a technology company that allows customers to use <a href=\"https:\/\/krebsonsecurity.com\/2024\/10\/the-global-surveillance-free-for-all-in-mobile-ad-data\/\">a real-time finder at and around nearly any location on a map of the world<\/a>, and view a time-lapse history of all mobile devices seen coming in and out of the specified area. <\/p>\n<\/div><\/div>\n\n\n\n<p>Babel Street consumes location data and other identifying information, (built into all Google Android and Apple mobile devices), that is collected by many websites and makes this available to dozens and sometimes hundreds of ad networks that may wish to bid on showing their ad to a particular user, the analysis states.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Non-for-Profit Updated privacy guidance for not-for-profit has been released by the Office of the Australian Information Commissioner. It includes a discussion on what to consider when engaging third-party providers, such as for fundraising, or software vendors.\u00a0For instance, when entering into arrangements with third parties, your non-for-profit should take reasonable steps to ensure that the third [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":9546,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[51,131,323,100,58,191],"class_list":["post-9541","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-artificial-intelligence","tag-clinical-trials","tag-consent-management-2","tag-cookies","tag-gdpr-compliance","tag-nis-2-directive"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-300x200.png",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-768x512.png",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-1024x682.png",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-200x200.png",200,200,true]},"post_excerpt_stackable":"<p>Non-for-Profit Updated privacy guidance for not-for-profit has been released by the Office of the Australian Information Commissioner. It includes a discussion on what to consider when engaging third-party providers, such as for fundraising, or software vendors.\u00a0For instance, when entering into arrangements with third parties, your non-for-profit should take reasonable steps to ensure that the third party\u2019s privacy practices meet the expectations of both your non-for-profit and the wider community, (donors, volunteers, and people who engage with the sector as clients and staff). It is important to read the terms of your agreement carefully, conduct periodic reviews, and ensure the third&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-300x200.png",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-768x512.png",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-1024x682.png",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280-200x200.png",200,200,true]},"post_excerpt_stackable_v2":"<p>Non-for-Profit Updated privacy guidance for not-for-profit has been released by the Office of the Australian Information Commissioner. It includes a discussion on what to consider when engaging third-party providers, such as for fundraising, or software vendors.\u00a0For instance, when entering into arrangements with third parties, your non-for-profit should take reasonable steps to ensure that the third party\u2019s privacy practices meet the expectations of both your non-for-profit and the wider community, (donors, volunteers, and people who engage with the sector as clients and staff). It is important to read the terms of your agreement carefully, conduct periodic reviews, and ensure the third&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 17 - 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: clinical research service providers, non-for-profit, commercially available AI\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 17 - 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: clinical research service providers, non-for-profit, commercially available AI\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-11-02T11:05:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-08T11:55:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 17 &#8211; 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI\",\"datePublished\":\"2024-11-02T11:05:22+00:00\",\"dateModified\":\"2025-07-08T11:55:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/\"},\"wordCount\":1693,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/seo-7092116_1280.png\",\"keywords\":[\"Artificial Intelligence\",\"clinical trials\",\"consent management\",\"cookies\",\"GDPR Compliance\",\"NIS 2 Directive\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/\",\"name\":\"Data protection digest 17 - 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/seo-7092116_1280.png\",\"datePublished\":\"2024-11-02T11:05:22+00:00\",\"dateModified\":\"2025-07-08T11:55:31+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: clinical research service providers, non-for-profit, commercially available AI\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/seo-7092116_1280.png\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/seo-7092116_1280.png\",\"width\":1280,\"height\":853,\"caption\":\"non-for-profit\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 17 &#8211; 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 17 - 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: clinical research service providers, non-for-profit, commercially available AI","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 17 - 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: clinical research service providers, non-for-profit, commercially available AI","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/","og_site_name":"TechGDPR","article_published_time":"2024-11-02T11:05:22+00:00","article_modified_time":"2025-07-08T11:55:31+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png","type":"image\/png"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 17 &#8211; 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI","datePublished":"2024-11-02T11:05:22+00:00","dateModified":"2025-07-08T11:55:31+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/"},"wordCount":1693,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png","keywords":["Artificial Intelligence","clinical trials","consent management","cookies","GDPR Compliance","NIS 2 Directive"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/","name":"Data protection digest 17 - 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png","datePublished":"2024-11-02T11:05:22+00:00","dateModified":"2025-07-08T11:55:31+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: clinical research service providers, non-for-profit, commercially available AI","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/11\/seo-7092116_1280.png","width":1280,"height":853,"caption":"non-for-profit"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-2112024-clinical-research-service-providers-non-for-profit-commercially-available-ai\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 17 &#8211; 31 Oct 2024: clinical research service providers, non-for-profit, commercially available AI"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=9541"}],"version-history":[{"count":18,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9541\/revisions"}],"predecessor-version":[{"id":10888,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/9541\/revisions\/10888"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/9546"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=9541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=9541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=9541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}