” To kick off, we are focusing on de-identification and privacy risk assessment, and welcome feedback on future topics of interest. “
https://www.nist.gov/itl/applied-cybersecurity/privacy-engineering/collaboration-space
[protecting people by good design, solid security, efficient processes and trusted services]
” To kick off, we are focusing on de-identification and privacy risk assessment, and welcome feedback on future topics of interest. “
https://www.nist.gov/itl/applied-cybersecurity/privacy-engineering/collaboration-space
Press release
Leifaden
Grove, a Kent pensions company, which relied on ‘misleading’ professional advice has been fined £40,000 by the Information Commissioner’s Office for being responsible for sending nearly two million direct marketing emails without consent. Grove utilised the servie of a third party marketing agent to carry out a range of marketing functions on their behalf, including lead generation.
Grove, by extension through this marketing agent, would work with “email providers”, who essentially provided a hosted marketing service by sending out “pre-approved emails” to opted-in subscribers contained within data sets which they themselves supplied.
Mitigating factors (that helped reduce the penalty):
1) “extensive consultation” with a recognized specialist data protection consultancy (even though this advise was obviously not quite right) as demonstrated awareness of obligations and a generally positive and http://pro.active approach to data protection
2) Number of complaints received was minimal.
3) No evidence that activity continued beyond period set out within the Notice
4) Cooperation with ICO investigation
https://ico.org.uk/media/action-weve-taken/mpns/2614585/grove-pensions-mpn-20190326.pdf
Fine amounts to 2.8% of company’s turnover.
Company “anonymized” customer information after two years, by deleting customer names from its system – but retained phone numbers for three more years. Argument that phone numbers were integral to the database were dismissed.
https://en.horten.dk/News/2019/Marts/Recommended-GDPR-fine-of-DKK-1-2-mill-to-Danish-taxi-company
https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=623051
see page 20, chapter 5.1
Light, high-level presentation at a FDA event in 2017 (?), with some *easy* examples of *bias* and *potential errors/issues*.. (also some pointer to GDPR discussion)