NormCyber data protection bulletin: 06th March 2023

Cookie Banners back in spotlight
The European Data Protection Board (“EDPB”) has recently published a report (the “Report”) about a number of ‘cookie law’ concerns, and has concluded that:
Cookie Banners back in spotlight
The European Data Protection Board (“EDPB”) has recently published a report (the “Report”) about a number of ‘cookie law’ concerns, and has concluded that:
Comment: The contents of this report are likely to guide EU regulator’s decisions about cookies in the future. For the avoidance of doubt, this report has no direct implications for the UK, except that UK websites that are also intended for users/visitors in the EU may be considered as ’fair game’ by EU regulators.
The importance of checking on those you rely on to process data for you
In two recent decisions, the French data protection authority, the CNIL, has emphasised the importance of data controllers auditing their data processors.
Case 1: A company relied on a third-party to ensure for password security and only holding personal data of inactive users for an appropriate retention period. These obligations were reflected in specific contractual instructions and in its defence the company pointed to its data processor’s contractual responsibility. However, the CNIL pointed out that the company did not audit its contractor to ensure that the contractual instructions were being followed and concluded that this meant the company had failed to comply with its responsibilities under the GDPR.
The company was fined €250,000
Case2: A company relied on a third-party to collect the consent of data subjects for direct marketing, i.e., to send marketing messages by email. The third party was contractually obliged to comply with the GDPR and ePrivacy rules applicable when obtaining such consents (but failed to do so, with the result that individuals received marketing emails without having given their prior consent). The company acknowledged that it had no control over the consent collection forms used by the third party and that it did not carry out any audit. The CNIL considered that the measures implemented by the company to ensure that valid consent was collected were insufficient and constituted a breach of the company’s obligations under both the GDPR and the ePrivacy applicable rules.
The amount of the fine is unknown.
Comment:
Although these two cases are in France, the same rules apply in the UK and demonstrate that:
The relevant ‘formula’ is: Contracts + audits = compliance
Further reading:
22nd February 2023 Threat Bulletin