Skip to main content
European Data Protection Board

European Data Protection Board

CompanyWikipedia

Search complete. 15 mentions across 8 episodes found for "European Data Protection Board".

Sep 29, 2026

Janni Lee B. Bang BrodersenGUEST
17:44
But if you take the GDPR, there are...
Janni Lee B. Bang BrodersenGUEST
17:47
So many things that are counterintuitive and also some of the guidelines coming from the EDPB, they are so hard to follow that sometimes it gets, you know, if you have the cloud guidance from the EDPB where it says you have to name all the sub-processors the whole way down in every software you use, and then you have to tell, for example, the employees when you process that data, about every system and all the chain down, but you also have to do it in a nice, transparent way.
Janni Lee B. Bang BrodersenGUEST
18:25
And you can do that.
Janni Lee B. Bang BrodersenGUEST
18:26
You can give that information that is technical and a lot of things for all the system where you have that data and then do it in a nice, easy way.
Sergio MaldonadoHOST
20:59
You know, since you mentioned this, I'm thinking also of a list of sub-processors.
Sergio MaldonadoHOST
21:03
And I know it's not as crazy here as it is in the EU with the EDPB now asking for so much transparency, cutting across all of these layers.
Sergio MaldonadoHOST
21:12
But to at least have a couple of layers of sub-processors, since everyone is relying on someone else, and there's more modularity, there's all these components that people recycle, some of them open source, and there's more and more people relying on the modules that others have published.
Sergio MaldonadoHOST
21:31
And so you see that whenever you buy a tool, you're already buying a cluster of solutions.
Robert BatemanHOST
0:00
The EDPB has just published its draft guidelines on the imposition of administrative fines, detailing how regulators should decide between financial penalties and other corrective measures.
Robert BatemanHOST
0:12
Today, we're going to walk through their proposed new five-step test.
Robert BatemanHOST
0:18
Welcome back to the Privacy Partnership podcast with me, Robert Bateman.
Robert BatemanHOST
0:23
So adopted for public consultation on the 17th of September, the EDPB's draft guidelines 04-2026 replace the rather old Article 29 Working Party guidance on setting fines from back in 2017.
Robert BatemanHOST
0:40
You might remember the EDPB's 2022 guidelines, which focused on the actual calculation of fines.
Robert BatemanHOST
0:47
These new draft guidelines take a step back.
Robert BatemanHOST
0:51
They address the legal preconditions for imposing a fine in the first place and how fines interplay with other corrective measures like warnings and reprimands.
Robert BatemanHOST
1:16
Can the infringement actually lead to an administrative fine? Article 83 of the GDPR lists most actionable obligations, but interestingly, it leaves out a few, like Article 24 regarding general technical and organisational measures.
Sergio MaldonadoHOST
16:45
I mean, you raised an important point.
Sergio MaldonadoHOST
16:48
We need DPIAs because we chose to incur in risks that were already predefined as requiring a DPIA, for example, in the EDPB or, you know, supervisory authorities guidelines, right? But now that we've fully matured and use privacy enhancing technologies and data minimization and key anonymity and all of these tools that everybody's using because they come also bundled with many of the layers in the stack that people are using.
Sergio MaldonadoHOST
17:21
then we don't need it.
Sergio MaldonadoHOST
17:23
This privacy by design is in there.

5 MINS LATER

Julian GageGUEST
22:34
Yeah, I mean, the definitive term that we all know and love is, you know, who makes the decisions and who guides that, which dictates who the controller is.
Julian GageGUEST
22:44
However, you have a bit more nuance to that.
Julian GageGUEST
22:47
Technically, the service provider, at least from EDPB or Working Party 29, I think it's the former, who had a good resource on this, who did recommend that it's actually okay to have some things you're doing as a service provider, say for analytics or business process improvement.
Julian GageGUEST
23:06
If you're crossing the line and improving the data you're getting from your customers into a commercial perspective, that's where you might cross the line.
Simon PillingerHOST
11:11
So I've just been spending quite a bit of time on anonymization, um, over the summer, which has been quite fun to do.
Simon PillingerHOST
11:17
So I was looking at taking what the work that I'd done over the last kind of five years or so and the principles that I'd applied in health research, look at the, um, European Data Protection Board's anonymization guidance that came on the back of SRB versus EDPS.
Simon PillingerHOST
11:31
There's a lot of letters in that sentence.
Simon PillingerHOST
11:33
And it was really interesting, just as much as anything to kind of compare what I'd done and some of the thinking I'd put together before the ICO's guidance came into being, and just go, "Actually, this has sort of stood up quite well," which is kind of nice to have.
Graeme DoyleGUEST
7:33
Look, this is an issue that's not, it's not unique to Ireland.
Graeme DoyleGUEST
7:36
Our colleagues in the European Data Protection Board are all dealing with the same thing.
Graeme DoyleGUEST
7:41
And actually, I just had lunch today with a friend who works in another regulator.
Graeme DoyleGUEST
7:45
They're seeing the very same thing, you know.
Dominic CramerHOST
54:53
The EU is also moving on this.
Dominic CramerHOST
54:55
So a report from the European Data Protection Board on smart glasses should soon be released as well.
Dominic CramerHOST
55:01
But I'm feeling a little bit more optimistic that something's actually going to happen and that we're not going to just live in this dystopian hellhole where everyone's... filming each other and can work out who you are through facial recognition just by looking at you so yeah that's my happy ending
Wojciech OleksiakHOST
55:21
beyond any doubt the sponsor of this episode is the word regulation
Paul BreitbarthHOST
21:45
But there are tons of companies out there who do fraud prevention with automated means.
Paul BreitbarthHOST
21:49
We've seen before in decisions from also published by the EDPB that in any case, they would allow legitimate interest as a legal basis for automated decision making for fraud prevention.
Paul BreitbarthHOST
22:02
But there now seems to be some sort of limit of what you can do as an organization to counter fraud in an automated way.
Paul BreitbarthHOST
22:10
So I'm very curious to see what detail there would be available here.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.