Locations
December was yet another busy month in the world of data and privacy so join us in this month's episode of the Fieldfisher's Data & Privacy Matters podcast to get some insight into the key stories.
Join the team as Lorna Cropper, Chloe Abbott and Anna Rawlinson discuss the European Data Protection Board’s (EDPB) opinion regarding AI models and personal data processing including the considerations that must be assessed on a case-by-case basis, particularly when using legitimate interests as a foundation for AI development.
Lorna then turns to the EU's progress on the General Purpose AI Code of Practice, which guides AI providers on compliance with the AI Act. This draft involves several working groups, and the next iteration is expected soon, aimed at ensuring seamless intergrationand practicality.
Anna follows on with updates on the ICO's consultation series on generative AI including lawful bases for using web-scraped data, the necessity for transparency, and the importance of designing AI products with data protection in mind from the outset.
Don't miss a thing, subscribe today!
Stay up to date by subscribing to the latest Data and Privacy insights from the experts at Fieldfisher.
Subscribe nowWith the EU's digital strategy advancing, it's clear that the GDPR cannot be looked at in isolation and its interplay with the EU AI Act, the EU Data Strategy and the Digital Services Package is something the EDPB wants to receive more consideration, which it flags in its response to the EU's second GDPR evaluation report.
The episode then covers the UK’s Data (Use and Access ) Bill, which proposes significant amendments to automated decision-making rules and multiple enforcement actions such as Italy's data protection regulator fining OpenAI €15 million for GDPR breaches and concludes with a discussion on Ofcom's new codes of practice aimed at addressing illegal online content under the UK's Online Safety Act.
Sources of the news discussed:
AI
- EDPB opinion on AI models: GDPR principles support responsible AI | European Data Protection Board
- Second Draft of the General-Purpose AI Code of Practice published, written by independent experts | Shaping Europe’s digital future
- Information Commissioner’s Office response to the consultation series on generative AI | ICO
EDPB
- Guidelines 02/2024 on Article 48 GDPR | European Data Protection Board
- https://www.edpb.europa.eu/system/files/2024-12/edpb_statement_20241203_ec_2nd_gdpr_evaluation_report_en.pdf
EU
- Adequacy update - EU-UK data adequacy review ahead of 2025 expiry under way | MLex | Specialist news and analysis on legal risk and regulation (paywall)
UK
- Data (Use and Access) Bill [HL] - Parliamentary Bills - UK Parliament
- Letter to Peter Kyle: Keep our right not to be subjected to decisions based solely on AI | Open Rights Group
Enforcement
- PRESS RELEASE - ChatGPT, the Italian Data Protection Authority closes the investigation.... - Italian Data Protection Authority
- Irish Data Protection Commission fines Meta €251 Million | 17/12/2024 | Data Protection Commission
- MLex | LinkedIn tells Irish court EUR310 million GDPR fine is ‘disproportionate’ (paywall)
- Meta asks High Court to overturn ‘wholly disproportionate’ €91m fine – The Irish Times
- Rogue employee - Manchester employee handed suspended prison sentence for illegally accessing personal information | ICO
Case law:
- Walker v Vardags Ltd KBD, 2024 WL 05011442 https://uk.westlaw.com/Document/I146AB8A0B6BC11EF900AF593C926A356/View/FullText.html (paywall)
Collective action
Online Safety
- Ofcom statement on illegal harms - Statement: Protecting people from illegal harms online - Ofcom
- Global Online Safety Regulators Network (Annual Report and Strategic Plan) GOSRN Annual Report 2024 GOSRN Three Year Strategic Plan Publication 2025 to 27