<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AI &#8211; DPO Centre</title>
	<atom:link href="https://www.dpocentre.ca/blog/category/ai/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dpocentre.ca</link>
	<description>Empowering Compliance, Protecting Data, Ensuring Trust. - DPO Centre</description>
	<lastBuildDate>Wed, 16 Jul 2025 15:11:25 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.dpocentre.ca/wp-content/uploads/2026/07/cropped-DPO-Centre-32x32.png</url>
	<title>AI &#8211; DPO Centre</title>
	<link>https://www.dpocentre.ca</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>5 steps to GDPR-compliant vendor due diligence </title>
		<link>https://www.dpocentre.ca/blog/5-steps-to-gdpr-compliant-vendor-due-diligence/</link>
		
		<dc:creator><![CDATA[Taylor Swann]]></dc:creator>
		<pubDate>Thu, 26 Jun 2025 15:02:36 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21999</guid>

					<description><![CDATA[<p>In this blog, we explain the difference between the roles of data controllers and processors and delve into the vendor due diligence process, providing North American organisations with essential steps to maintain GDPR compliance.&#160; You’ll learn how to:&#160; Overview According to a report by technavio, the global outsourcing market is expected to grow by $88.8 [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/5-steps-to-gdpr-compliant-vendor-due-diligence/">5 steps to GDPR-compliant vendor due diligence </a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In this blog, we explain the difference between the roles of data controllers and processors and delve into the vendor due diligence process, providing North American organisations with essential steps to maintain GDPR compliance.&nbsp;</p>



<p class="wp-block-paragraph">You’ll learn how to:&nbsp;</p>



<ul class="wp-block-list">
<li><a href="#Step-1"><strong>Review the vendor’s data handling practices</strong>&nbsp;</a></li>



<li><a href="#Step-2" data-type="internal" data-id="#Step-2"><strong>Assess policies and procedures</strong>&nbsp;</a></li>



<li><a href="#Step-3"><strong>Evaluate technical security measures</strong>&nbsp;</a></li>



<li><a href="#Step-4"><strong>Review international data transfer controls and processes</strong>&nbsp;</a></li>



<li><a href="#Step-5"><strong>Mitigate risks &amp; finalise the Data Processor Agreement (DPA)</strong>&nbsp;</a></li>
</ul>



<h2 class="wp-block-heading"><strong><strong><strong>Overview </strong></strong></strong></h2>



<p class="wp-block-paragraph">According to a report by <strong><a href="https://www.technavio.com/report/business-process-outsourcing-market-size-industry-analysis?utm_source=prnewswire&amp;utm_medium=pressrelease&amp;utm_campaign=aidriver1_1_report_week05_2025&amp;utm_content=IRTNTR44588" target="_blank" data-type="link" data-id="https://www.technavio.com/report/business-process-outsourcing-market-size-industry-analysis?utm_source=prnewswire&amp;utm_medium=pressrelease&amp;utm_campaign=aidriver1_1_report_week05_2025&amp;utm_content=IRTNTR44588" rel="noreferrer noopener">technavio</a></strong>, the global outsourcing market is expected to grow by $88.8 billion between 2024 and 2029, with a compound annual growth rate of 6.8%.&nbsp;</p>



<p class="wp-block-paragraph">Outsourcing specific processes, or even entire business functions, can enhance efficiency and allow companies to focus on their core strengths. However, when you have vendors handling personal data, it&#8217;s critical to understand the associated data protection responsibilities of both parties.&nbsp;</p>



<p class="wp-block-paragraph">Under the General Data Protection Regulation (GDPR), vendors include any third parties, partners, or suppliers with access to personal data &#8211; not just traditional service providers.&nbsp;</p>



<p class="wp-block-paragraph">Organizations are legally required to safeguard personal data, and failure to do so can result in fines and reputational harm. Ensuring that your vendors also meet GDPR obligations is a key part of maintaining compliance.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>Understanding GDPR roles: Controller vs processor</strong>&nbsp;</h2>



<p class="wp-block-paragraph">The GDPR distinguishes between a data ‘controller’ and a ‘processor’ to clarify their respective roles and responsibilities in managing personal data.&nbsp;</p>



<ul class="wp-block-list">
<li>A ‘controller’ decides how and why personal data is collected and processed&nbsp;</li>



<li>A ‘processor’ handles personal data on behalf of the controller, following on their instructions&nbsp;</li>
</ul>



<p class="wp-block-paragraph"><strong>Data controllers</strong> hold the highest level of compliance responsibility, even if a third-party vendor is handling the day-to-day processing.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong>Data processors</strong> have some direct legal obligations, including notifying the controller of any data breach, implementing appropriate data security measures, and keeping a record of data processing activities.&nbsp;&nbsp;</p>



<h4 class="wp-block-heading"><strong><strong><strong><strong>Let’s look at a real-world example:</strong>&nbsp;</strong></strong></strong></h4>



<p class="wp-block-paragraph"><em>A North American healthcare provider (controller) collects patient data from individuals in the EU to provide medical services. The data is stored and managed on a third-party cloud storage platform (provider) and includes information such as names, addresses, and medical histories.&nbsp;</em>&nbsp;</p>



<p class="wp-block-paragraph">In this example, the healthcare provider must ensure any personal data is processed in strict accordance with the GDPR. This includes providing clear privacy notices, establishing an appropriate lawful basis, and safeguarding the security of the data, including any onward transfers of personal data outside the EU.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Before using the third-party cloud storage platform, the healthcare provider must:&nbsp;</p>



<ul class="wp-block-list">
<li>Ensure the vendor’s data protection practices meet GDPR standards&nbsp;</li>



<li>Identify and mitigate any risks before sharing personal data&nbsp;</li>



<li>Implement clear contracts that outline roles, responsibilities, and security requirements&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Once onboarded, the cloud storage platform must follow the healthcare company’s instructions and maintain robust safeguards. If a data breach occurs, the cloud storage provider is expected to notify the healthcare company without undue delay – ideally within 48 hours, though this should be determined in each contract.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong>Reminder:</strong> Under the GDPR, controllers have up to 72 hours after becoming aware of a personal data breach to report it to the relevant regulatory authority. If the breach poses a high risk to individuals, they must also be informed directly.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>5 essential steps for effective due diligence</strong></h2>



<p class="wp-block-paragraph"><strong>A best practice due diligence process typically starts with a questionnaire and follows these 5 key steps:</strong>&nbsp;&nbsp;</p>



<h4 class="wp-block-heading" id="Step-1"><strong>Step 1: Review the vendor’s data handling practices</strong></h4>



<p class="wp-block-paragraph">A due diligence questionnaire should request the vendor’s privacy policy and any voluntary or mandatory risk assessment documents, such as Data Protection Impact Assessments (DPIAs), relating to the services offered.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Key details to establish:&nbsp;</p>



<ul class="wp-block-list">
<li>How personal data will be collected&nbsp;</li>



<li>Where it will be stored&nbsp;</li>



<li>Who will have access to the data&nbsp;</li>



<li>Use of sub-processors, including their data handling practices (sub-processors are third parties engaged by the vendor who may access the personal data)&nbsp;</li>



<li>What the retention periods are (the GDPR requires data to be kept no longer than necessary)&nbsp;</li>



<li>If they have any certifications, such as Cyber Essentials Plus, ISO9001, or ISO27001/27701, which demonstrate a commitment to strong data protection practices across the organization&nbsp;</li>
</ul>



<h4 class="wp-block-heading" id="Step-2"><strong><strong><strong><strong>Step 2: Assess policies and procedures</strong></strong></strong></strong><a id="_msocom_1"></a></h4>



<p class="wp-block-paragraph">The next step is to evaluate the vendor’s data protection policies and procedures to ensure they align with GDPR requirements.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">These should include at least:&nbsp;</p>



<ul class="wp-block-list">
<li>Privacy policy and privacy notice&nbsp;</li>



<li>Data breach response procedure&nbsp;</li>



<li>Data Subject Access Request (DSAR) procedure&nbsp;</li>



<li>Data sharing processes&nbsp;</li>



<li>Employee data protection training programs&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The vendor needs to demonstrate that appropriate controls are in place for data processing, including any sub-processors they may use, and that these controls are regularly audited and maintained.&nbsp;&nbsp;</p>



<h4 class="wp-block-heading" id="Step-3"><strong>Step 3: Evaluate technical security measures</strong></h4>



<p class="wp-block-paragraph">Ensure the vendor has robust technical safeguards to protect personal data from unauthorized access, alternation, disclosure, or destruction.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">These measures may include:&nbsp;</p>



<ul class="wp-block-list">
<li>Encryption: Converts data into a code to prevent unauthorized access&nbsp;</li>



<li>Access controls: Authenticates users and restricts access to systems and data&nbsp;</li>



<li>Firewalls: Monitors and controls incoming and outgoing network traffic based on predetermined security rules&nbsp;</li>



<li>Intrusion detection systems (IDS): Detects malicious activity within the network&nbsp;</li>



<li>Security incident and event management (SIEM) systems: Analyses security alerts generated by applications and network hardware in real time&nbsp;</li>



<li>Regular security audits: Systemic evaluations of IT systems to measure how well they conform to a set of established criteria&nbsp;&nbsp;</li>
</ul>



<h4 class="wp-block-heading" id="Step-4"><strong>Step 4: Review international data transfer controls and processes</strong>&nbsp;</h4>



<p class="wp-block-paragraph">If personal data is stored or processed outside the EEA and/or UK, the vendor must demonstrate that a valid international transfer mechanism is in place.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Your contract should require the vendor to implement appropriate safeguards for both their own transfers and any onward transfer by sub-processors. This often involves using Standard Contractual Clauses (SCCs) or another GDPR-approved mechanism.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">If the data is considered high risk, a supporting DPIA should also be provided.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong><a href="Read: International data transfers: Explaining EU SCCs, UK Addendum and UK IDTA" target="_blank" rel="noreferrer noopener">International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA | DPO Centre</a></strong></p>



<h4 class="wp-block-heading" id="Step-5"><strong>Step 5: Mitigate risks &amp; finalise the Data Processor Agreement (DPA)</strong>&nbsp;</h4>



<p class="wp-block-paragraph">If any risks have been identified during the due diligence process, the vendor needs to resolve them before moving forward. For example, if the vendor lacks intrusion alerts, they should implement system monitoring and provide evidence.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong>The final step is to draft a Data Processing Agreement (DPA)</strong>, which should include:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>General information</strong> – Purpose, duration, data categories, and GDPR responsibilities of both parties&nbsp;</li>



<li><strong>Security measures</strong> – Technical and organizational safeguards required of the processor&nbsp;</li>



<li><strong>Sub-processors</strong> – Whether sub-processing is allowed and under what conditions&nbsp;</li>



<li><strong>Breach notifications</strong> – Requirement to notify the controller without undue delay in the event of a breach&nbsp;</li>



<li><strong>Audits and inspections</strong> – Controller’s should secure the right to verify compliance through audits&nbsp;</li>



<li><strong>End-of-contract provisions</strong> – Instructions on returning or deleting data at contract termination&nbsp;</li>



<li><strong>Liabilities and indemnities </strong>–<strong> </strong>controllers should require processors to indemnify them against all costs, claims, damages, and expenses incurred because of their actions. Controllers typically seek unlimited liability, while processors should negotiate a cap.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">For a template DPA <strong><a href="https://www.dpocentre.com/resources/gdpr-toolkit/" target="_blank" data-type="link" data-id="https://www.dpocentre.com/resources/gdpr-toolkit/" rel="noreferrer noopener">download our GDPR Policy Toolkit</a></strong>&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>Summary</strong></h2>



<p class="wp-block-paragraph">Conducting vendor due diligence is essential for identifying and mitigating risk and ensuring GDPR compliance. It provides an opportunity to evaluate a vendor’s operational procedures data protection practices before entering into a contract.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">An effective due diligence process should include a questionnaire covering five key areas: data handling practices, policies and procedures, technical security measures, international data transfers, and risk mitigation prior to drafting a Data Processing Agreement (DPA).&nbsp;</p>



<p class="wp-block-paragraph">These steps also apply to existing suppliers or outsourced services. However, given the number of suppliers most organizations work with, it&#8217;s often more practical to start with a pre-qualification risk assessment. This helps prioritize which vendors require further review based on factors like GDPR applicability, risk level, and the type of data processed.&nbsp;</p>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph">The DPO Centre has extensive experience helping North American organizations meet their GDPR obligations when working with third-party vendors. <strong><a href="https://www.dpocentre.ca/contact-us/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/contact-us/" rel="noreferrer noopener">Contact us</a></strong> today for expert support with your vendor due diligence processes. </p>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><a href="http://Lead generation and the GDPR: A guide for North American businesses" target="_blank" rel="noreferrer noopener"><strong>Lead generation and the GDPR: A guide for North American businesses</strong>&nbsp;</a></li>



<li><strong><a href="https://www.dpocentre.ca/data-retention-strategies-for-gdpr-compliance/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/data-retention-strategies-for-gdpr-compliance/" rel="noreferrer noopener">Data retention strategies for GDPR compliance</a></strong> </li>



<li><strong><strong><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/">How GDPR territorial scope impacts North American businesses</a></strong></strong></li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong><strong>For more news and insights about data protection follow The DPO Centre on</strong> <a href="https://uk.linkedin.com/company/dpo-centre" target="_blank" rel="noreferrer noopener"><strong>LinkedIn</strong></a></strong></p>



<figure class="wp-block-image aligncenter size-large is-resized"><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel=" noreferrer noopener"><img fetchpriority="high" decoding="async" width="1024" height="536" src="https://www.dpocentre.ca/wp-content/uploads/2025/03/DPIA-sign-up-advert-1024x536.jpg" alt="DPIA sign up advert" class="wp-image-21828" style="width:600px" title="5 steps to GDPR-compliant vendor due diligence  1"></a></figure>



<p class="wp-block-paragraph"></p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/5-steps-to-gdpr-compliant-vendor-due-diligence/">5 steps to GDPR-compliant vendor due diligence </a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Lead generation and the GDPR: A guide for North American businesses</title>
		<link>https://www.dpocentre.ca/blog/lead-generation-and-the-gdpr-a-guide-for-north-american-businesses/</link>
		
		<dc:creator><![CDATA[Taylor Swann]]></dc:creator>
		<pubDate>Tue, 27 May 2025 09:02:45 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21970</guid>

					<description><![CDATA[<p>In this blog, we break down the essentials of GDPR compliance for lead generation, focusing on what North American businesses need to know when targeting or engaging with individuals in the EU and UK. Whether your lead generation is managed in-house or through a third-party provider, understanding your obligations under European and UK data privacy [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/lead-generation-and-the-gdpr-a-guide-for-north-american-businesses/">Lead generation and the GDPR: A guide for North American businesses</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In this blog, we break down the essentials of GDPR compliance for lead generation, focusing on what North American businesses need to know when targeting or engaging with individuals in the EU and UK. Whether your lead generation is managed in-house or through a third-party provider, understanding your obligations under European and UK data privacy laws is critical. Any personal data you collect from these regions must be processed lawfully, transparently, and securely.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Since the General Data Protection Regulation (GDPR) came into effect in 2018, marketing strategies have undergone a significant transformation, with a definite shift toward inbound methodologies. Attracting engagement from customers, rather than pursuing prospects directly has become the modern standard. Outdated tactics such as buying prospect lists, cold calling, and sending unsolicited emails have been replaced by a focus on creating valuable, engaging content, and tailored experiences.&nbsp;</p>



<p class="wp-block-paragraph"><em>For the purposes of our discussion, we consider the EU GDPR and the UK GDPR under the same umbrella, focussing on the common aspects for businesses operating in both or either the EU and the UK. There are specific differences and nuances in the legislations that are not covered here and may be applicable to your organization. For further advice, please speak to your Privacy Officer/Data Protection Officer.</em>&nbsp;</p>



<h2 class="wp-block-heading"><br><strong><strong><strong>Establishing a lawful basis under the GDPR</strong>&nbsp;</strong></strong></h2>



<p class="wp-block-paragraph">The General Data Protection Regulation (GDPR) provides the legal framework for the collection, processing, and storage of personal data of individuals in the EU (with the UK GDPR applying to individuals in the UK).&nbsp;</p>



<p class="wp-block-paragraph">North American organizations must establish an appropriate lawful basis for processing personal data of EU and UK individuals. This means that before collecting any personal data, you must first identify and document the lawful basis for doing so.&nbsp;</p>



<h4 class="wp-block-heading"><strong><strong><strong>There are six lawful bases under the GDPR:</strong></strong></strong></h4>



<p class="wp-block-paragraph"><strong>Consent</strong> – where an individual has given consent for their personal data to be processed&nbsp;</p>



<p class="wp-block-paragraph"><strong>Legitimate Interests</strong> &#8211; where the processing of an individual&#8217;s personal data is necessary for the legitimate interests of a business or organization, unless there is a good reason to protect the individual’s personal data, which then overrides those legitimate interests&nbsp;</p>



<p class="wp-block-paragraph"><strong>Contract</strong> &#8211; where the processing is necessary for the performance of a contract a business or organization has with an individual&nbsp;</p>



<p class="wp-block-paragraph"><strong>Legal Obligation</strong> – where the processing is necessary for a business or organization to comply with the law&nbsp;</p>



<p class="wp-block-paragraph"><strong>Vital Interests </strong>– where the processing is necessary to protect someone’s life&nbsp;</p>



<p class="wp-block-paragraph"><strong>Public Task</strong> – where the processing is necessary for the performance of a task in the public interest or for official functions, and the task or function has a clear basis in the law&nbsp;</p>



<p class="wp-block-paragraph"><strong><em>After determining a lawful basis, you must document it and ensure the information is clearly stated in your privacy policy and privacy notice.</em></strong>&nbsp;</p>



<p class="wp-block-paragraph">Choosing the most appropriate lawful basis is essential, as it is difficult to change later without good reason. The lawful bases commonly used for processing personal data for marketing and lead generation purposes are consent and legitimate interests. For certain types of marketing activities, consent is the only appropriate lawful basis to use. A data privacy officer (DPO) can provide guidance on the most suitable lawful basis for your personal data processing.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong><strong><strong>ePrivacy Directive and PECR</strong></strong></strong></h2>



<p class="wp-block-paragraph">In addition to the GDPR, North American businesses undertaking digital marketing and lead generation activities in the EU and/or UK must also comply with regulations governing electronic communications, cookies, and tracking technologies.&nbsp;</p>



<p class="wp-block-paragraph"><strong>The EU’s ePrivacy Directive</strong>, often referred to as the ‘cookie law’, covers key areas related to electronic communications and privacy, including consent for cookies and marketing communications.&nbsp;</p>



<p class="wp-block-paragraph"><strong>The UK’s Privacy and Electronic Communications Regulations (PECR)</strong> sets out the rules and requirements for electronic communications and privacy within the UK. The legislation is the UK’s implementation of the EU’s ePrivacy Directive, and it sits alongside the UK GDPR.&nbsp;</p>



<h4 class="wp-block-heading"><strong>Privacy rules for electronic communications</strong>&nbsp;</h4>



<p class="wp-block-paragraph">The ePrivacy Directive and PECR have specific standards that apply when processing the personal data of individuals in the EU and UK through electronic communications and other marketing tactics.&nbsp;</p>



<p class="wp-block-paragraph"><strong>You must:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Obtain consent before collecting an individual’s personal data&nbsp;</li>



<li>Provide clear and transparent information about how the personal data will be used</li>



<li>Collect only the personal data that is necessary&nbsp;</li>



<li>Obtain consent before placing non-essential cookies on a user’s device&nbsp;&nbsp;</li>



<li>Provide an easy way to opt-out&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><br><strong><strong><strong>Understanding consent</strong></strong></strong><a id="_msocom_1"></a></h2>



<p class="wp-block-paragraph">Consent is a fundamental aspect of data privacy law. The GDPR defines consent as:&nbsp;</p>



<p class="wp-block-paragraph"><em>any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. – </em><em>Article 4(11)</em>&nbsp;</p>



<p class="wp-block-paragraph">In certain situations, or for specific processing activities, consent is the <strong>only</strong> lawful basis that can be used.&nbsp;</p>



<p class="wp-block-paragraph">Consent is also mandated by the ePrivacy Directive and PECR, where the use of cookies, tracking pixels, web beacons, and other similar technologies are used to collect personal data for online advertising and targeting.&nbsp;</p>



<h5 class="wp-block-heading"><strong>Consider this example: How CompanyX reaches potential customers</strong></h5>



<p class="wp-block-paragraph">CompanyX wants to connect with website visitors who have not yet made a purchase. A tracking pixel from a social media provider is integrated onto their website. The pixel tracks users after they have left the site, allowing CompanyX to display targeted ads for their products when that user visits other websites.&nbsp;</p>



<p class="wp-block-paragraph">This strategy falls under the ePrivacy Directive and PECR and requires consent. Both use the definition of consent found within the GDPR (above).&nbsp;</p>



<h4 class="wp-block-heading"><strong><strong><strong>How to obtain consent</strong></strong></strong></h4>



<p class="wp-block-paragraph">Under the GDPR, organizations must obtain explicit consent from customers before collecting their personal data. Lead generation tactics, such as pre-ticked boxes, implied consent, or bundling consent in with other actions, are no longer allowed.&nbsp;</p>



<p class="wp-block-paragraph">Here is a breakdown of the factors required for obtaining consent under the GDPR:&nbsp;</p>



<p class="wp-block-paragraph"><strong>Freely given:</strong> Consent must be given voluntarily, without coercion or manipulation. It should be a genuine choice for the individual, not forced.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Specific:</strong> Consent must be tied to the exact purpose. Individuals should be informed what their personal data will be used for, and their agreement limited to that specific use. When processing has multiple purposes, consent must be obtained for all of them.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Informed:</strong> Individuals must be given information about the processing of their personal data before giving consent. This includes knowing what data will be collected, who is collecting it, why, how long it will be kept, and any other relevant details.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Unambiguous:</strong> Consent should be clear and easy to understand.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Indication of wishes</strong>: Consent must be given through an affirmative action, including written, electronic, and oral statements. For example, a tick box on a website or a written consent form. Pre-ticked boxes or inactivity do not constitute consent.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Withdrawable:</strong> Individuals who change their mind have the right to withdraw their consent at any time. The withdrawal process must be as easy as giving consent.&nbsp;</p>



<h4 class="wp-block-heading"><strong>How to collect, record and manage consent</strong></h4>



<p class="wp-block-paragraph">In line with the GDPR’s accountability principle, which states that organizations must take responsibility for what they do with personal data, there is a requirement to evidence the process of obtaining consent.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">This means that in addition to securing permission from an individual to process their data, you also need to keep records and evidence the process.&nbsp;</p>



<p class="wp-block-paragraph">Let’s look at the critical aspects of consent management a little closer and the details you should document:&nbsp;</p>



<p class="wp-block-paragraph"><strong>Who consented:</strong> The name of the individual or other identifier (e.g. online username, session ID).&nbsp;</p>



<p class="wp-block-paragraph"><strong>When they consented:</strong> A dated document or online records with a timestamp. For oral consent, a note with the time and date of the conversation.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What they were told at the time:</strong> A master copy of a document or data capture form containing their consent statement and a copy of the privacy notice or other privacy information, including version numbers and dates that match the date consent was given. For oral consent, your records should include a copy of the script used at that time.&nbsp;</p>



<p class="wp-block-paragraph"><strong>How they consented:</strong> A copy of the relevant document or data capture form. For online consent, your records should include the data submitted and a timestamp to link it to the relevant data capture form. For oral consent, the whole conversation does not need to be recorded, only a note of the time the conversation took place.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Whether they have withdrawn consent:</strong> If so, when?&nbsp;<br>&nbsp;<br>Review and refresh the consent process if anything changes. It is recommended that you consider updating consent every two years.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong><strong><strong>Relying on Legitimate Interests</strong></strong></strong></h2>



<p class="wp-block-paragraph">The GDPR states that the processing of personal data for direct marketing purposes may be considered a valid reason or legitimate interest (GDPR Recital 47). However, as marketing is generally in the interests of the business, the validity of using legitimate interests as a lawful basis for processing data must be carefully considered, balancing any possible consequences for the individual.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">A Legitimate Interests Assessment (LIA) is a useful tool that can be used to identify and consider this lawful basis as a possible justification for processing personal data under the GDPR.&nbsp;</p>



<p class="wp-block-paragraph">An LIA is comprised of the following three-part tests:&nbsp;</p>



<ol start="1" class="wp-block-list">
<li>The purpose test (identify the legitimate interest)&nbsp;&nbsp;</li>



<li>The necessity test (consider if the processing is necessary)&nbsp;&nbsp;</li>



<li>The balancing test (consider the individual’s interests)&nbsp;&nbsp;</li>
</ol>



<p class="wp-block-paragraph">Using legitimate interests as a lawful basis will only be permissible if it does not affect the fundamental rights and freedoms of individuals, which always take precedence. This means that while using legitimate interests as a lawful basis, the focus is not on preventing every negative outcome or consequence but on ensuring that any potential negative consequences are not excessive or out of proportion compared to the intended benefits or purposes. It’s about maintaining balance.&nbsp;</p>



<h5 class="wp-block-heading"><strong><strong>Consider this example: How CompanyX delivers personalised ads&nbsp;</strong></strong></h5>



<p class="wp-block-paragraph">When PersonA became a customer of CompanyX a year ago, they provided their email address for communication purposes. During the first communication, CompanyX informed PersonA of two key points: (i) their email address would be used to advertise similar CompanyX products on social media, and (ii) they had the right to object to this processing at any time.&nbsp;</p>



<p class="wp-block-paragraph">CompanyX then added PersonA&#8217;s email address to its customer database and shared it with a social media provider. This collaboration allowed CompanyX to match its list of customer email addresses with those held by the social media provider. As a result, CompanyX gained the ability to precisely target and market similar products to PersonA via their social media feed.&nbsp;</p>



<p class="wp-block-paragraph">This strategy falls under the GDPR and can rely on the lawful basis of legitimate interests.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong><strong>Working with lead generation providers</strong></strong><a id="_msocom_1"></a></h2>



<p class="wp-block-paragraph">Lead generation companies use a variety of marketing strategies to provide qualified leads that can potentially be turned into customers.&nbsp;</p>



<p class="wp-block-paragraph">However, it is important to note that your data processing responsibilities remain and must be upheld, regardless of the use of a third-party service.&nbsp;</p>



<p class="wp-block-paragraph">The GDPR makes a distinction between organizations and third parties by using the terms ‘data controller’ and ‘data processor’.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Data controller:</strong> This is a person or organization that decides how and why personal data is collected and used. Controllers have overall control over the data, therefore, the highest level of compliance responsibility.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Data processor:</strong> This is a person or organization that handles personal data on behalf of the controller. Processors are responsible for ensuring the data processing is in line with the instructions of the controller, in addition to other legal obligations, including notifying the controller in the event of a data breach.&nbsp;</p>



<h4 class="wp-block-heading"><strong><strong>Is your lead generation partner meeting GDPR requirements?</strong></strong></h4>



<p class="wp-block-paragraph">As a controller, it is important that you conduct due diligence on any third-party company you plan on using. You need to confirm the third-party&#8217;s compliance with the GDPR and any other relevant data privacy laws, such as the ePrivacy Directive and PECR, as detailed above.&nbsp;</p>



<p class="wp-block-paragraph">It is vital that you ensure the outsourced lead generation company has sufficient technical and organizational measures in place to protect the personal data they are processing on your behalf.&nbsp;</p>



<p class="wp-block-paragraph">For more detailed information about conducting due diligence on your data processors, read</p>



<p class="wp-block-paragraph"> <strong><a href="https://www.dpocentre.com/vendor-due-diligence-gdpr-compliance-5-practical-steps/" data-type="link" data-id="https://www.dpocentre.com/vendor-due-diligence-gdpr-compliance-5-practical-steps/" target="_blank" rel="noreferrer noopener">Vendor due diligence and GDPR compliance with 5 practical steps</a></strong>.</p>



<h2 class="wp-block-heading"><br>Summary</h2>



<p class="wp-block-paragraph">Lead generation is an important aspect of business growth, but it must be conducted in line with the relevant data privacy laws. For North American organizations handling the personal data of EU and UK individuals, these include the EU GDPR, UK GDPR, ePrivacy Directive, and PECR.&nbsp;</p>



<p class="wp-block-paragraph">Before undertaking a lead generation strategy, it is essential that the correct measures are in place, including assigning the most appropriate lawful basis and ensuring the obligations and responsibilities as a data controller are understood and implemented.&nbsp;</p>



<p class="wp-block-paragraph">By understanding and adhering to the relevant regulations, organizations can prevent any future non-compliance issues as well as strengthening customer trust, confidence, and engagement.&nbsp;</p>



<p class="wp-block-paragraph">Confident customers lead to increased loyalty, which translates into becoming a more successful and sustainable business.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong><a href="https://www.dpocentre.ca/contact-us/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/contact-us/" rel="noreferrer noopener">Contact us</a> </strong>to find out how an outsourced data privacy service can support you in maximising marketing ROI while staying compliant with EU and UK data privacy laws.&nbsp;</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Visit <strong><a href="https://www.dpocentre.ca" data-type="link" data-id="https://www.dpocentre.ca">The DPO Centre</a></strong> to find out how an outsourced data privacy service can support you in maximising marketing ROI while staying compliant with EU and UK data privacy laws.&nbsp;</p>



<p class="wp-block-paragraph">Alternatively, you can get in touch by filling in the form below.&nbsp;</p>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><strong><a href="https://www.dpocentre.ca/eu-ai-act-compliance-north-american-organizations/" data-type="link" data-id="https://www.dpocentre.ca/eu-ai-act-compliance-strategies/" target="_blank" rel="noreferrer noopener">EU AI Act Compliance: What North American organizations need to know</a></strong></li>



<li><strong><a href="https://www.dpocentre.ca/data-retention-strategies-for-gdpr-compliance/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/data-retention-strategies-for-gdpr-compliance/" rel="noreferrer noopener">Data retention strategies for GDPR compliance</a></strong> </li>



<li><strong><strong><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/">How GDPR territorial scope impacts North American businesses</a></strong></strong></li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong>Don’t miss out on the latest data protection updates – stay informed with our fortnightly newsletter, </strong><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel="noreferrer noopener"><strong>The DPIA</strong></a></p>



<figure class="wp-block-image aligncenter size-large is-resized"><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="536" src="https://www.dpocentre.ca/wp-content/uploads/2025/03/DPIA-sign-up-advert-1024x536.jpg" alt="DPIA sign up advert" class="wp-image-21828" style="width:600px" title="Lead generation and the GDPR: A guide for North American businesses 2"></a></figure>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/lead-generation-and-the-gdpr-a-guide-for-north-american-businesses/">Lead generation and the GDPR: A guide for North American businesses</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Data retention strategies for GDPR compliance</title>
		<link>https://www.dpocentre.ca/blog/data-retention-strategies-for-gdpr-compliance/</link>
		
		<dc:creator><![CDATA[Taylor Swann]]></dc:creator>
		<pubDate>Tue, 29 Apr 2025 12:46:33 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21915</guid>

					<description><![CDATA[<p>Data retention strategies for GDPR compliance matter, even for North American organizations. The UK and EU&#8217;s General Data Protection Regulation (GDPR) has extra territorial reach, meaning it applies to any organization, regardless of location, if that organization offers goods or services to, or monitors the behaviour of individuals in the EU or UK and processes [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/data-retention-strategies-for-gdpr-compliance/">Data retention strategies for GDPR compliance</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Data retention strategies for GDPR compliance matter, even for North American organizations. The UK and EU&#8217;s General Data Protection Regulation (GDPR) has extra territorial reach, meaning it applies to any organization, regardless of location, if that organization offers goods or services to, or monitors the behaviour of individuals in the EU or UK and processes their personal data.<br><br>Here are some of the most common questions organizations have about data retention and GDPR compliance:</p>



<ul class="wp-block-list">
<li><strong><em>How long should different types of personal data be retained?</em></strong>&nbsp;</li>



<li><strong><em>What makes an effective data retention policy and schedule?</em></strong>&nbsp;</li>



<li><strong><em>What responsibilities do data controllers, processors and sub-processors have for data retention?</em></strong>&nbsp;</li>
</ul>



<p class="wp-block-paragraph">In this blog, we dive into these questions and share practical guidance – from determining the lifespan of different types of personal data to creating an effective data retention policy and schedule.&nbsp;</p>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading"><br><strong><strong>GDPR and data retention</strong></strong></h2>



<p class="wp-block-paragraph">The General Data Protection Regulation (GDPR) has set new standards for the way businesses handle EU personal data, including what type of data is collected and the length of time it is kept. If your organization processes the data of individuals in the EU or European Economic Area (EEA), implementing a robust data retention policy is crucial.&nbsp;</p>



<p class="wp-block-paragraph">The GDPR’s principles of Storage Limitation, Minimisation, and Accuracy play a vital role in shaping such a policy.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Storage Limitation:</strong> Ensure personal data is not retained beyond the necessary time period&nbsp;</p>



<p class="wp-block-paragraph"><strong>Minimisation:</strong> Collect only the minimal amount of data required&nbsp;</p>



<p class="wp-block-paragraph"><strong>Accuracy:</strong> Maintain accurate, up-to-date, and reliable information&nbsp;</p>



<p class="wp-block-paragraph">In other words, the processing of personal data must be <strong>adequate, relevant, and limited</strong> to what is necessary in relation to the specific purposes of the processing. You must only process personal data that is needed for the operations of your business.&nbsp;</p>



<h3 class="wp-block-heading"><br><strong><strong>The GDPR doesn’t define exactly what ‘no longer than necessary’ means, so how can you judge timeframes?</strong>&nbsp;</strong></h3>



<p class="wp-block-paragraph">Necessity is a key factor in an effective data retention timeframe and is determined by your purpose for processing. In other words, your reason for handling and storing personal data will dictate the length of time you keep it.&nbsp;</p>



<p class="wp-block-paragraph">Storage periods will depend on several elements, such as the industry sector, the type of data processing, and any other regulatory requirements that apply. However, in some circumstances there is a statutory retention. For example, finance records in the UK and EU are generally maintained for 7 years (6 years plus current year), in accordance with the Companies Act.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Under the GDPR, the key requirement for data retention is that the chosen duration must be justified, and this decision must be documented.&nbsp;</p>



<h3 class="wp-block-heading"><strong><strong>The documents you will need to produce:</strong>&nbsp;</strong></h3>



<ul class="wp-block-list">
<li><strong>A data retention policy</strong> – This provides a general overview of the data management practices and is a broad document outlining how the organization manages its data, how long it keeps certain types of data, and the roles and responsibilities of staff&nbsp;</li>



<li><strong>A data retention schedule </strong>– This is<strong> </strong>also known as a disposal schedule and is a more detailed document, specifying the exact retention period for different classes of records and the action needed to be taken at the end of the retention period&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Data retention roles: Controllers, processors and sub-processors&nbsp;</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Whether you’re a data controller, processor, or sub-processor, understanding your responsibilities and obligations is essential. It is important to manage data retention in a way that ensures compliance with the General Data Protection Regulation (GDPR) and meets your business needs.&nbsp;</p>



<h4 class="wp-block-heading"><strong><strong>Data controllers</strong></strong><a id="_msocom_1"></a></h4>



<p class="wp-block-paragraph">Data controllers determine the purpose of any personal data processed, and the means of processing.&nbsp;</p>



<p class="wp-block-paragraph">A data controller is primarily responsible for determining the data retention timeframe, as they decide the purposes and means of processing personal data.&nbsp;</p>



<p class="wp-block-paragraph">If you are the data controller, you must ensure you have a comprehensive data retention policy and schedule in place and communicate this to any data processors or sub-processors you have engaged, such as cloud storage companies or marketing agencies. As a controller, you carry the primary responsibility for complying with data protection laws.&nbsp;</p>



<h4 class="wp-block-heading"><strong>Data processors</strong></h4>



<p class="wp-block-paragraph">Data processors process personal data on behalf of the controller, and sub-processors are third parties engaged by the processor.&nbsp;</p>



<p class="wp-block-paragraph">Data processors and sub-processors are responsible for processing personal data on behalf of the controller. They must follow the controller’s instructions, including abiding by a data retention timeframe, which should be set out in the contract or data processing agreement. Details should also include what will happen to the personal data once the contract is terminated.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading"><br><strong><strong>Top 4 data retention challenges and how to solve them</strong></strong></h2>



<h4 class="wp-block-heading"><strong>1. Changing regulatory landscape</strong></h4>



<p class="wp-block-paragraph">Data protection laws continue to develop at a rapid pace around the world. Existing EU and UK privacy&nbsp;laws are also frequently updated. Organizations can struggle to keep up with these changes, especially when processing and storing personal data across multiple jurisdictions.</p>



<h5 class="wp-block-heading"><strong>Advice:</strong> <strong>Keep updated on the latest data protection laws</strong>&nbsp;</h5>



<p class="wp-block-paragraph">Seek advice from an experienced Data Protection Officer (DPO) who specializes in EU and UK data protection laws&nbsp;– a dedicated DPO will regularly review and update your data retention policies and schedules and ensure they are compliant with the latest regulations.&nbsp;</p>



<p class="wp-block-paragraph"><strong><em>Solution</em></strong><em> – Hire a dedicated Data Protection Officer (DPO)</em>&nbsp;</p>



<p class="wp-block-paragraph"></p>



<h4 class="wp-block-heading"><strong><strong>2. Data subject awareness</strong></strong></h4>



<p class="wp-block-paragraph">Individuals are increasingly aware of their rights and more likely to make a data subject access request (DSAR). This can place a burden on an organization’s data retention framework, as it must be equipped to efficiently locate, retrieve, and respond to a DSAR, providing the requested data within a strict timeframe. <strong><a href="https://www.dpocentre.com/the-dpo-centre-answers-dsar-faqs/" target="_blank" data-type="link" data-id="https://www.dpocentre.com/the-dpo-centre-answers-dsar-faqs/" rel="noreferrer noopener">Read our DSAR FAQs</a> </strong>for more information.</p>



<p class="wp-block-paragraph"><strong>Advice: Proactively prepare for data subject requests</strong></p>



<p class="wp-block-paragraph">Ensure your organization has a well-documented and tested process for handling Data Subject Access Requests (DSARs). This includes training relevant staff, having clear workflows in place, and knowing where personal data is stored. &nbsp;<br>&nbsp;<br><strong><em>Solution</em></strong><em> – establish a robust DSAR response process</em></p>



<p class="wp-block-paragraph"></p>



<h4 class="wp-block-heading"><strong>3. Data volume</strong><a id="_msocom_1"></a></h4>



<p class="wp-block-paragraph">It can be difficult to manage the vast quantities of data that are collected daily from various digital channels, such as email, social media, websites, and virtual stores. Not to mention paper archive records, which can create a significant challenge for companies to organize. </p>



<h5 class="wp-block-heading"><strong>Advice: Implement data minimisation practices</strong></h5>



<p class="wp-block-paragraph">Only collect what is absolutely necessary. A practical tip is to conduct a data audit. This involves reviewing the types of personal data your organization collects and identifying what is needed. For example, an online store collects customer names, addresses and payment information for order fulfilment. However, the store also collects dates of birth and marital status, which, depending on the types of products sold, could be considered excessive and in breach of the GDPR’s data minimisation principle.&nbsp;</p>



<p class="wp-block-paragraph"><strong><em>Solution</em></strong><em> – Conduct a data audit and implement data minimisation practices</em>&nbsp;</p>



<p class="wp-block-paragraph"></p>



<h4 class="wp-block-heading"><strong>4. Over-retention</strong></h4>



<p class="wp-block-paragraph">Without specific rules on timeframes, organizations can often keep information far beyond its intended or necessary retention period. This can increase operational costs for storage, backup and retrieval. There is also the heightened risk of reputational damage if a cyber-attack or breach were to occur, which is a breach of the GDPR’s 5<sup>th</sup> principle, and can potentially result in regulatory action.</p>



<h5 class="wp-block-heading">Advice: Avoid keeping information for too long</h5>



<p class="wp-block-paragraph">It is important to have a clear data retention schedule for each type of data. Automated tools can be used to manage the schedule and delete or anonymise data that is no longer needed. Employees also need to be made aware of data retention policies and schedules, so they understand what to do with the data.&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph"><strong><em>Solution</em></strong><em> – Implement a clear data retention schedule</em>&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>Best practice tips for data retention</strong></h2>



<p class="wp-block-paragraph">Effective management of personal data can help you to reduce risks and maintain compliance with data protection laws.&nbsp;</p>



<p class="wp-block-paragraph">Here are some helpful tips for your data retention strategy:&nbsp;</p>



<p class="wp-block-paragraph">To ensure compliance with the AI Act, organizations need to focus on critical areas such as staff training, robust corporate governance, and strong cybersecurity and data protection measures</p>



<ul class="wp-block-list">
<li>Conduct a data audit&nbsp;</li>



<li>Only collect data that is necessary for your purposes&nbsp;</li>



<li>Implement a data retention policy and schedule for each type of data collected&nbsp;</li>



<li>If data is kept for longer or shorter periods than the retention schedule, the reason for this needs to be documented&nbsp;</li>



<li>Review processing activities on a regular basis and add new ones to the schedule&nbsp;</li>



<li>Train staff on policy and schedule requirements, ensuring awareness of the operational requirements before any data is deleted, understanding that deleting data too soon is also considered a breach&nbsp;</li>



<li>Where there is a recommendation to archive older data, this can be in an electronic format and filed in a separate electronic folder, suitably labeled as holding archive material&nbsp;</li>



<li>Paper archive records need to be indexed and once retention is met, they should be destroyed safely and securely, using a confidential waste provider or cross cutting shredder&nbsp;</li>
</ul>



<p class="wp-block-paragraph">See also the Retention Policy template in our<a href="https://www.dpocentre.com/resources/gdpr-toolkit/" data-type="link" data-id="https://www.dpocentre.com/resources/gdpr-toolkit/" target="_blank" rel="noopener"> </a><strong><a href="https://www.dpocentre.com/resources/gdpr-toolkit/" target="_blank" data-type="link" data-id="https://www.dpocentre.com/resources/gdpr-toolkit/" rel="noreferrer noopener">free-to-download GDPR Toolkit</a></strong><a href="https://www.dpocentre.com/resources/gdpr-toolkit/" data-type="link" data-id="https://www.dpocentre.com/resources/gdpr-toolkit/" target="_blank" rel="noopener">&nbsp;</a></p>



<h2 class="wp-block-heading"><br>Summary</h2>



<p class="wp-block-paragraph">There are several challenges for businesses when it comes to data retention and GDPR compliance. The key is to understand your organization’s purpose for collecting personal data and align this purpose with the principles of data minimisation, storage limitation and accuracy.&nbsp;</p>



<p class="wp-block-paragraph">Documentation is essential for GDPR compliance, and a comprehensive data retention policy and schedule are a requirement. However, it is important to remember that effective data management is not just about compliance.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Individuals are more likely to engage with organizations they trust to handle their personal data responsibly. Investing in robust data management practices and having a well-defined data retention schedule is a win-win for both compliance and customer satisfaction.&nbsp;</p>



<p class="wp-block-paragraph"><em>The DPO Centre has one of the largest teams of Data Protection Officers (DPOs), working globally with over 1,000 organizations across the spectrum of industry sectors, delivering GDPR compliance solutions.</em>&nbsp;</p>



<p class="wp-block-paragraph"><em>If you need help with your GDPR compliance or you are considering an outsourced data protection solution, please </em><strong><em>get in touch</em></strong><em> with our team</em></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>For more news and insights about data protection follow The DPO Centre on</strong> <a href="https://uk.linkedin.com/company/dpo-centre" target="_blank" rel="noreferrer noopener"><strong>LinkedIn</strong></a>&nbsp;</p>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><strong><a href="https://www.dpocentre.ca/eu-ai-act-compliance-strategies/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/eu-ai-act-compliance-strategies/" rel="noreferrer noopener">EU AI Act Compliance part 4: Essential strategies for North American organizations</a></strong></li>



<li><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/" data-type="link" data-id="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/" target="_blank" rel="noreferrer noopener"></a><strong><strong><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/">How GDPR territorial scope impacts North American businesses</a></strong></strong></li>



<li><a href="https://www.dpocentre.ca/gdpr-guide-for-saas-companies-eu-uk/" target="_blank" rel="noreferrer noopener"></a><strong><a href="https://www.dpocentre.ca/data-privacy-day-2025-canada/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/data-privacy-day-2025-canada/" rel="noreferrer noopener">Data Privacy Day 2025: Navigating privacy in Canada</a></strong></li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong>Don’t miss out on the latest data protection updates – stay informed with our fortnightly newsletter, </strong><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel="noreferrer noopener"><strong>The DPIA</strong></a></p>



<figure class="wp-block-image aligncenter size-large is-resized"><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="536" src="https://www.dpocentre.ca/wp-content/uploads/2025/03/DPIA-sign-up-advert-1024x536.jpg" alt="DPIA sign up advert" class="wp-image-21828" style="width:600px" title="Data retention strategies for GDPR compliance 3"></a></figure>



<p class="wp-block-paragraph"></p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/data-retention-strategies-for-gdpr-compliance/">Data retention strategies for GDPR compliance</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EU AI Act Compliance part 4: Essential strategies for North American organizations</title>
		<link>https://www.dpocentre.ca/blog/eu-ai-act-compliance-strategies/</link>
		
		<dc:creator><![CDATA[Joel Fisk]]></dc:creator>
		<pubDate>Thu, 03 Apr 2025 14:20:40 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21874</guid>

					<description><![CDATA[<p>As we wrap up our four-part EU AI Act blog series, this final installment explores some of the key strategies Canadian and US organizations can implement to keep ahead of the curve and ensure EU AI Act compliance. For North American organizations, this often means implementing compliance measures that go beyond domestic requirements, particularly in [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/eu-ai-act-compliance-strategies/">EU AI Act Compliance part 4: Essential strategies for North American organizations</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">As we wrap up our four-part <strong>EU</strong> <strong>AI Act blog series</strong>, this final installment explores some of the key strategies Canadian and US organizations can implement to keep ahead of the curve and ensure EU AI Act compliance.</p>



<p class="wp-block-paragraph">For North American organizations, this often means implementing compliance measures that go beyond domestic requirements, particularly in areas like algorithmic transparency and bias testing.</p>



<p class="wp-block-paragraph">If you’re developing or deploying AI systems for EU markets, your compliance journey is likely to be complex and demanding, especially if you’re managing high-risk systems. But compliance has to be approached as more than a tick-box exercise. It’s an opportunity to lead the way in responsible AI innovation, building trust with users and regulators alike.</p>



<p class="wp-block-paragraph">By embracing compliance as a catalyst for more transparent AI usage, organizations can turn regulatory demands into a competitive advantage.</p>



<p class="wp-block-paragraph">Before we dive into the specifics of the essential compliance strategies you should consider, here’s a quick overview of the main points we’ve previously addressed:</p>



<h2 class="wp-block-heading"><br><strong>What we’ve covered so far</strong></h2>



<p class="wp-block-paragraph">By following our blog series, you’ll already have taken the first steps in preparing for compliance with the EU AI Act. Specifically, you should have:</p>



<ul class="wp-block-list">
<li>Determined whether your AI system falls under the AI Act based on how it affects EU markets</li>



<li>Identified any exemptions (e.g. research, military use)</li>



<li>Clarified your role in the AI value chain (i.e. Provider, Deployer or another role)</li>



<li>Understood the purpose of your system, and whether it’s classified as ‘prohibited’, ‘high-risk’ or a General Purpose AI model (GPAI)</li>
</ul>



<h4 class="wp-block-heading"><br><strong>The EU AI Act comes into full effect in August 2026</strong></h4>



<p class="wp-block-paragraph">There are certain provisions coming into force earlier, such as a ban on systems that perform prohibited functions. It&#8217;s important organizations make sure they give themselves plenty of time and resources to meet all aspects of the AI Act’s implementation deadlines.</p>



<p class="wp-block-paragraph">More detailed guidance on the timelines and deadlines, risk-based classifications, and compliance obligations, can be found in parts 1-3 of this blog series:</p>



<h4 class="wp-block-heading"><strong>Compliance with the AI Act blog series</strong></h4>



<ul class="wp-block-list">
<li><a><strong>Part 1: Essential knowledge for North American organizations</strong></a></li>



<li><a><strong>Part 2: Understanding ‘high-risk’ activities</strong></a></li>



<li><a><strong>Part 3: Roles and requirements for North American organizations</strong></a></li>
</ul>



<p class="wp-block-paragraph">Let’s now look at some of the essential strategies you can implement to support your AI Act compliance journey.</p>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading"><br><strong>Key strategies for EU AI Act compliance</strong><a id="_msocom_1"></a></h2>



<h4 class="wp-block-heading"><br><strong>1. Staff awareness and training</strong></h4>



<p class="wp-block-paragraph">All organizations intending to use AI systems in any capacity should carefully consider the potential impact of those systems and engage in staff awareness and upskilling.</p>



<p class="wp-block-paragraph">Training is essential to ensure all team members understand their roles in compliance and are able to implement the AI Act’s requirements.</p>



<p class="wp-block-paragraph">A comprehensive training program should address the AI Act’s key requirements and include role-specific details. For example, AI developers may need more in-depth technical training, while Compliance Officers need to focus on documentation and regulatory obligations.</p>



<p class="wp-block-paragraph">Tailor staff training programs to the specific risks associated with the type of data processed and the system’s intended use. For example, employees working with systems that have a greater impact on individuals, such as those making credit decisions affecting EU customers, may need more extensive training than those handling non-sensitive functions.</p>



<p class="wp-block-paragraph"></p>



<h4 class="wp-block-heading"><strong>2. Establishing strong corporate governance</strong></h4>



<p class="wp-block-paragraph">For Canadian and US organizations providing or deploying high-risk or General Purpose AI (GPAI) systems in EU markets, strong corporate governance is essential to demonstrate and maintain compliance. Without certain elements in place, organizations may struggle to meet the Act’s specific requirements and maintain the necessary compliance documentation.</p>



<p class="wp-block-paragraph">To build and maintain strong corporate governance, organizations should focus on:</p>



<ul class="wp-block-list">
<li><strong>Implementing effective risk and quality management systems</strong> to oversee and mitigate risks and help identify and address any issues early on</li>



<li><strong>Ensuring robust cybersecurity and data protection practices</strong> are in place to safeguard sensitive personal data and protect against data breaches</li>



<li><strong>Developing accountability structures</strong> with clear lines of responsibility to ensure compliance efforts are coordinated and effective</li>



<li><strong>Monitoring AI systems regularly</strong> and reporting on their performance and compliance status</li>
</ul>



<h5 class="wp-block-heading"><strong>Cybersecurity and data protection practices</strong></h5>



<p class="wp-block-paragraph">To meet the stringent requirements of the AI Act, organizations should prioritize strong cybersecurity and data protection practices. This means embedding effective risk and quality management systems into your operations.</p>



<p class="wp-block-paragraph">Without these practices, organizations may fail to meet specific requirements of the Act and will likely struggle to produce and maintain other compliance documentation that’s required.</p>



<p class="wp-block-paragraph"><strong>For cybersecurity aspects</strong>, practices should include implementing robust infrastructure security with strict access controls, having a detailed incident response plan, and ensuring regular security audits to identify vulnerabilities.</p>



<p class="wp-block-paragraph"><strong>The data protection requirements</strong> of the AI Act overlap with the EU’s General Data Protection Regulation (GDPR) in several areas and <a href="https://www.dpocentre.com/the-data-protection-act-2018-the-7-principles-of-the-gdpr/" target="_blank" rel="noreferrer noopener"><strong>key principles</strong></a>,&nbsp; particularly around transparency and accountability.</p>



<p class="wp-block-paragraph">While the GDPR focuses on the protection of personal data, the AI Act covers the broader development and regulation of AI systems. This includes not only safeguarding personal data but also managing overall AI risks to ensure fairness, prevent harm, and promote transparency.</p>



<p class="wp-block-paragraph">You can use the GDPR principles and current data protection practices to support compliance with the AI Act by integrating <strong><a href="https://www.dpocentre.com/what-is-privacy-by-design/" target="_blank" rel="noreferrer noopener">‘Privacy by Design’</a></strong>&nbsp; into your AI systems, conducting Impact Assessments for high-risk AI applications, and maintaining clear documentation of data protection activities.</p>



<p class="wp-block-paragraph"></p>



<h4 class="wp-block-heading"><strong>3. Being ready for upcoming guidelines and templates</strong><a id="_msocom_1"></a></h4>



<p class="wp-block-paragraph"><strong>Available in the coming months</strong> – the EU is developing specific codes of practice and templated documentation to help organizations meet their compliance obligations.</p>



<p class="wp-block-paragraph">We’ll provide updates in further blogs as these become available.<a id="_msocom_2"></a></p>



<p class="wp-block-paragraph"></p>



<h4 class="wp-block-heading"><strong>4. Following ethical AI principles and practices</strong></h4>



<p class="wp-block-paragraph">Although guidelines and practical applications of the EU AI Act are still evolving, its core principles are well established in ethical AI frameworks. Organizations using AI, especially with personal data or human impact, must understand how the system works, its purpose, and its limits. Documenting these aspects supports best practice and accountability.</p>



<p class="wp-block-paragraph">Organizations must also <strong>comply with transparency requirements</strong> under existing data protection laws in addition to the specifics of the AI Act.</p>



<p class="wp-block-paragraph">Finally, it’s essential to conduct a <strong>risk assessment</strong> of how the AI system may impact individuals who interact with it and the organization’s liability and reputation if anything should go wrong. This proactive approach to AI governance is highly beneficial and can mostly be implemented without needing to tailor it for specific regulations.</p>



<p class="wp-block-paragraph"></p>



<h4 class="wp-block-heading"><strong>5. Seeking expert guidance</strong></h4>



<p class="wp-block-paragraph">There are resources available to support your compliance journey. This includes<strong> <a href="https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/" target="_blank" rel="noreferrer noopener">the EU AI Act Compliance Checker</a></strong>&nbsp;, a tool designed to help organizations verify that their AI system aligns with regulatory requirements.</p>



<p class="wp-block-paragraph">However, the nuances of the AI Act are complex, and we urge every organization uncertain of its obligations to seek professional advice.</p>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading"><br><strong>Key takeaways</strong></h2>



<ul class="wp-block-list">
<li>To ensure compliance with the AI Act, organizations need to focus on critical areas such as staff training, robust corporate governance, and strong cybersecurity and data protection measures</li>



<li>Embedding ethical AI principles and maintaining transparency are essential for Canadian and US companies developing AI systems that serve EU markets, especially those impacting individuals and handling personal data</li>



<li>Although practical guidelines for the Act are still to come, businesses should proactively implement these strategies and prepare for future updates</li>
</ul>



<p class="wp-block-paragraph"><strong>In conclusion:</strong> Staying ahead of AI regulations isn’t just about compliance – it&#8217;s an opportunity to build trust and lead the way in responsible AI innovation.</p>



<p class="wp-block-paragraph"><a id="_msocom_1"></a></p>



<p class="wp-block-paragraph">The DPO Centre has developed a comprehensive AI Audit and Impact Assessment service. If you need support beginning or continuing your AI compliance journey with confidence, please<strong> <a href="https://www.dpocentre.ca/contact-us/" target="_blank" rel="noreferrer noopener">contact us</a></strong>.<a id="_msocom_1"></a></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><strong><a href="https://www.dpocentre.ca/eu-ai-act-compliance-organizations-requirements/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/privacy-in-canada-usa-2024-and-2025-expectations/" rel="noreferrer noopener">EU AI Act compliance part 3: Roles and requirements for North American organizations</a></strong></li>



<li><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/" data-type="link" data-id="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/" target="_blank" rel="noreferrer noopener"></a><strong><strong><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/">How GDPR territorial scope impacts North American businesses</a></strong></strong></li>



<li><a href="https://www.dpocentre.ca/gdpr-guide-for-saas-companies-eu-uk/" target="_blank" rel="noreferrer noopener"></a><a><strong>GDPR guide for SaaS companies expanding into EU &amp; UK markets</strong></a></li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong>Don’t miss out on the latest data protection updates – stay informed with our fortnightly newsletter, </strong><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel="noreferrer noopener"><strong>The DPIA</strong></a></p>



<figure class="wp-block-image aligncenter size-large is-resized"><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="1024" height="536" src="https://www.dpocentre.ca/wp-content/uploads/2025/03/DPIA-sign-up-advert-1024x536.jpg" alt="DPIA sign up advert" class="wp-image-21828" style="width:600px" title="EU AI Act Compliance part 4: Essential strategies for North American organizations 4"></a></figure>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/eu-ai-act-compliance-strategies/">EU AI Act Compliance part 4: Essential strategies for North American organizations</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EU AI Act compliance part 3: Roles and requirements for North American organizations</title>
		<link>https://www.dpocentre.ca/blog/eu-ai-act-compliance-organizations-requirements/</link>
		
		<dc:creator><![CDATA[Joel Fisk]]></dc:creator>
		<pubDate>Thu, 27 Mar 2025 16:22:06 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21847</guid>

					<description><![CDATA[<p>Part 3 of our four-part guide to EU AI Act compliance examines how North American organizations can navigate the Act&#8217;s requirements, including organizational roles and key obligations. The AI Act will come into full effect in August 2026, 24 months after its official publication, although certain provisions will come into force earlier. For a detailed [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/eu-ai-act-compliance-organizations-requirements/">EU AI Act compliance part 3: Roles and requirements for North American organizations</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Part 3 of our four-part guide to EU AI Act compliance examines how North American organizations can navigate the Act&#8217;s requirements, including organizational roles and key obligations.</p>



<p class="wp-block-paragraph">The AI Act will come into full effect in August 2026, 24 months after its official publication, although certain provisions will come into force earlier. For a detailed understanding of the AI Act’s implementation timeline, and further information about the risk-based classification of AI systems, please refer to Part 1 and Part 2 of our blog series:</p>



<p class="wp-block-paragraph"><a href="https://www.dpocentre.ca/eu-ai-act-compliance-north-american-organizations/" target="_blank" rel="noreferrer noopener"><strong>Compliance with the AI Act Part 1: Timeline and important deadlines</strong></a></p>



<p class="wp-block-paragraph"><strong><a href="https://www.dpocentre.ca/eu-ai-act-compliance-high-risk-activities/" target="_blank" rel="noreferrer noopener">Compliance with the AI Act Part 2: What is ‘high-risk’ activity?</a></strong></p>



<p class="wp-block-paragraph">Whether your organization develops AI chatbots for customer service, uses predictive algorithms for credit assessment, or deploys image recognition software, understanding your role and responsibilities under the EU AI Act is crucial for maintaining compliance when operating in European markets.<a id="_msocom_1"></a><a id="_msocom_1"></a></p>



<h2 class="wp-block-heading"><br><strong><strong>Navigating the AI Act’s global reach</strong></strong></h2>



<p class="wp-block-paragraph">Similar to the EU’s General Data Protection Regulation (GDPR), the AI Act has extra-territorial reach, making it a significant law with global implications. Its provisions apply to any organization marketing, deploying, or using an AI system that affects individuals or businesses in the EU, no matter where the system is developed or operated.</p>



<p class="wp-block-paragraph"><strong>For example, if an AI system hosted in Toronto or San Francisco generates data or decisions that impact individuals or businesses in any of the EU’s 27 Member States, that system must comply with the AI Act.</strong></p>



<p class="wp-block-paragraph">The aim of the extra-territorial scope is to ensure the fundamental rights of EU residents are respected, regardless of international boundaries. This approach seeks to promote a consistent standard of ethical AI practices, encouraging all organizations to uphold high standards of <strong>accountability and transparency</strong>.</p>



<h2 class="wp-block-heading"><br><strong><strong>Key organizational roles under the AI Act</strong></strong></h2>



<p class="wp-block-paragraph">Compliance obligations for organizations are determined by two main factors:</p>



<ol class="wp-block-list">
<li><strong>The risk level of the AI system</strong></li>



<li><strong>The organization’s role in the supply chain</strong></li>
</ol>



<p class="wp-block-paragraph">The risk classification of AI systems is detailed in <a href="https://www.dpocentre.ca/eu-ai-act-compliance-high-risk-activities/"><strong>Part 2</strong></a> of our blog series. Therefore, let’s explore the various categories of roles organizations can play and the specific obligations associated with each.<a id="_msocom_1"></a></p>



<h2 class="wp-block-heading"><br><strong><strong><strong><strong>What role does your organization play?</strong></strong></strong></strong></h2>



<p class="wp-block-paragraph">Under the AI Act, organizations fall into one of six distinct roles, each with its own set of obligations:</p>



<ul class="wp-block-list">
<li><strong>Provider</strong><br>An individual or organization that develops an AI system and places it on the market. Providers are responsible for ensuring their system meets the necessary requirements of the AI Act.</li>



<li><strong>Deployer</strong><br>An individual or organization using an AI system developed by a Provider. A Deployer’s responsibilities under the AI Act are minimal if they use the AI system without changing it. If they modify the system significantly or use it under their own name or trademark, they take on the Provider’s responsibilities, as if they were the original Provider.</li>



<li><strong>Distributor</strong><br>An individual or organization making an AI system available on the EU Market, acting as an intermediary between provider and user.</li>



<li><strong>Importer</strong><br>Any natural or legal person based in the EU who brings an AI system into the EU market from outside the EU. This role is particularly relevant for North American organizations selling AI systems to EU customers.</li>



<li><strong>Product Manufacturer</strong><br>An individual or organization introducing or putting into service an AI system on the EU market as part of another product and brands it with their own name or trademark.</li>



<li><strong>Authorized Representative</strong><br>An individual or organization based in the EU who’s been formally appointed by a Provider located outside the EU. This role is especially important for North American companies without EU offices.</li>
</ul>



<p class="wp-block-paragraph">Representatives are responsible for managing and fulfilling regulatory obligations and documentation required by the AI Act on behalf of Providers. This is similar to the GDPR Representative role, although documentation is more detailed and extensive. This is because the AI Act involves complex regulatory requirements for AI systems, covering a broad range of technical, operational, and safety aspects.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="948" height="1024" src="https://www.dpocentre.ca/wp-content/uploads/2025/03/EU-AI-Act-compliance-organization-requirements.png-948x1024.png" alt="EU AI Act compliance organization requirements.png" class="wp-image-21860" title="EU AI Act compliance part 3: Roles and requirements for North American organizations 5" srcset="https://www.dpocentre.ca/wp-content/uploads/2025/03/EU-AI-Act-compliance-organization-requirements.png-948x1024.png 948w, https://www.dpocentre.ca/wp-content/uploads/2025/03/EU-AI-Act-compliance-organization-requirements.png-278x300.png 278w, https://www.dpocentre.ca/wp-content/uploads/2025/03/EU-AI-Act-compliance-organization-requirements.png-768x830.png 768w, https://www.dpocentre.ca/wp-content/uploads/2025/03/EU-AI-Act-compliance-organization-requirements.png-1421x1536.png 1421w, https://www.dpocentre.ca/wp-content/uploads/2025/03/EU-AI-Act-compliance-organization-requirements.png.png 1500w" sizes="(max-width: 948px) 100vw, 948px" /></figure>



<p class="wp-block-paragraph"><br></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading"><strong><strong>Provider or Deployer?&nbsp;</strong></strong></h2>



<p class="wp-block-paragraph">Carefully assess whether you’re a Provider or Deployer, as this will significantly affect your compliance responsibilities. It’s important to make sure how you deploy an AI system doesn’t inadvertently make you responsible as a Provider.</p>



<p class="wp-block-paragraph">While most obligations fall on Providers, Deployers also have various responsibilities.</p>



<h4 class="wp-block-heading"><br><strong><strong>Common requirements for Providers AND Deployers</strong></strong></h4>



<p class="wp-block-paragraph"><strong>AI literacy</strong> – Providers and Deployers must ensure all staff and agents using AI systems have the appropriate knowledge. This depends on their roles and the associated risks, but is similar to mandatory data protection training under the GDPR.</p>



<p class="wp-block-paragraph"><strong>Transparency</strong> – Providers and Deployers must ensure any AI system interacting with individuals (termed a ‘natural person’) meets transparency obligations, such as clearly marking content generated or manipulated by AI.</p>



<p class="wp-block-paragraph"><strong>Registration</strong> – similar to data protection registration with a supervisory authority, Providers and Deployers must register the AI system in the EU’s database.</p>



<h3 class="wp-block-heading"><br><strong><strong><strong><strong>Provider-specific obligations</strong></strong></strong></strong></h3>



<p class="wp-block-paragraph">Because Providers design, develop, and bring AI systems to market, they bear primary responsibility for ensuring they meet safety and ethical standards. They also control the creation and operation of AI systems, so are crucial to ensuring systems meets the required standards for safety, effectiveness, and ethics.</p>



<h5 class="wp-block-heading"><strong>Transparency and accountability: Two key principles of the AI Act</strong></h5>



<p class="wp-block-paragraph">Providers must ensure their AI system is easy to understand, and clearly communicate its functionalities, limitations, and potential risks. This helps users know exactly what to expect and how to use it safely and effectively.</p>



<h4 class="wp-block-heading"><br><strong>Key requirements for Providers include:</strong></h4>



<ul class="wp-block-list">
<li><strong>Imposing responsibilities on importers and distributors</strong> – ensure all parties in the AI supply chain know about and adhere to their compliance standards, including completion of conformity assessments </li>



<li><strong>Establishing a risk management system</strong> – a structured process to regularly review the AI system, identifying, evaluating and mitigating any risks</li>



<li><strong>Implementing effective data governance</strong> – develop clear procedures and processes for managing training data, including ensuring diversity and establishing protocols for data handling and data protection</li>



<li><strong>Preparing technical documentation</strong> – create detailed and accessible documentation about the AI system’s design, functionality, and performance to enable user understanding BEFORE it goes on market</li>



<li><strong>Maintaining event logs</strong> – set up automatic logging systems to track the AI system’s operations and any issues that may arise</li>



<li><strong>Creating usage documentation for Deployers</strong> – provide Deployers with clear and comprehensive guides on how to use the AI system <strong><em>(Deployers must also maintain documentation relevant to their use of the system, if it differs)</em></strong></li>



<li><strong>Establishing human oversight</strong> – design the AI system to allow for human intervention and monitoring (also impacts Deployers)</li>



<li><strong>Ensuring accuracy and robustness</strong> – confirm the AI system is reliable and resilient in its operations, and suitable for its intended purpose</li>



<li><strong>Implementing cybersecurity measures</strong> – integrate strong cybersecurity practices to protect the AI system from potential threats</li>



<li><strong>Maintaining a quality management system</strong> – establish a quality management system to oversee ongoing development of the AI system</li>



<li><strong>Addressing issues and conformity</strong> – quickly address any issues with the AI system and withdraw any systems that don’t conform or comply with compliance standards<strong> <em>(also impacts Deployers)</em></strong></li>



<li><strong>Completing documentation and assessments </strong>– complete all documentation and conformity assessments accurately, and retain for at least 10 years</li>



<li><strong>Appointing a Representative</strong> – if needed, appoint a Representative to support compliance obligations and be a point of contact between Provider and regulatory authorities, particularly relevant for North American Providers based outside the EU</li>



<li><strong>Cooperating with supervisory authorities</strong> – be ready to liaise with regulatory bodies, providing requested information and helping with inspections or audits to show compliance</li>



<li><strong>Imposing responsibilities on importers and distributors</strong> – ensure all parties in the AI supply chain know about and adhere to their compliance standards, including completion of conformity assessments</li>
</ul>



<h2 class="wp-block-heading"><br><strong>In summary</strong></h2>



<p class="wp-block-paragraph">The EU AI Act is a landmark piece of legislation, setting the first global standards for the responsible development and deployment of artificial intelligence systems.</p>



<p class="wp-block-paragraph">As with many new regulations, the EU’s AI legislation has sparked concerns and debates among various stakeholders, including industry associations, tech companies, and legal professionals.</p>



<p class="wp-block-paragraph">Their concerns echo the initial criticisms that surrounded the introduction of the EU’s General Data Protection Regulation (GDPR). Namely, the potential difficulties for organizations and businesses in interpreting and implementing its provisions.</p>



<p class="wp-block-paragraph">However, despite its complexity, the AI Act, much like the GDPR, has a structured approach that makes implementation more manageable. There are clear definitions for the six roles in the AI supply chain. Each role comes with specific compliance obligations, with the Provider role having the greatest responsibilities.</p>



<h5 class="wp-block-heading"><br><strong>Strategic Considerations for North American Organizations</strong></h5>



<p class="wp-block-paragraph">With the AI Act coming into full effect in August 2026, it’s essential North American organizations operating in EU markets familiarize themselves with the compliance obligations and how they apply.&nbsp;</p>



<p class="wp-block-paragraph">Complying with the AI Act could serve as a market differentiator and a unique selling point that attracts clients and partners who value responsible and ethical AI practices.</p>



<p class="wp-block-paragraph"><strong>If your organization would benefit from specialist data protection or AI governance advice for EU or UK markets, please</strong> <strong><a href="https://www.dpocentre.ca/contact-us/" target="_blank" rel="noreferrer noopener">contact us</a></strong>.</p>



<p class="wp-block-paragraph"><a id="_msocom_1"></a></p>



<h2 class="wp-block-heading"><br><strong>EU AI Act compliance part 4: Essential strategies for North American organizations</strong></h2>



<p class="wp-block-paragraph">Coming next, in the final part of this blog series, we explore some of the best practices to guide you in meeting compliance requirements.</p>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><a href="https://www.dpocentre.ca/eu-ai-act-compliance-high-risk-activities/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/privacy-in-canada-usa-2024-and-2025-expectations/" rel="noreferrer noopener"><strong>EU AI Act compliance part 2:</strong> <strong>Understanding ‘high-risk’ activities</strong></a></li>



<li><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/" rel="noreferrer noopener"><a><strong>How GDPR territorial scope impacts North American businesses</strong></a></a></li>



<li><a href="https://www.dpocentre.ca/gdpr-guide-for-saas-companies-eu-uk/" target="_blank" rel="noreferrer noopener"><a><strong>GDPR guide for SaaS companies expanding into EU &amp; UK markets</strong></a></a></li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong>Don’t miss out on the latest data protection updates – stay informed with our fortnightly newsletter, </strong><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel="noreferrer noopener"><strong>The DPIA</strong></a></p>



<figure class="wp-block-image aligncenter size-large is-resized"><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="1024" height="536" src="https://www.dpocentre.ca/wp-content/uploads/2025/03/DPIA-sign-up-advert-1024x536.jpg" alt="DPIA sign up advert" class="wp-image-21828" style="width:600px" title="EU AI Act compliance part 3: Roles and requirements for North American organizations 6"></a></figure>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/eu-ai-act-compliance-organizations-requirements/">EU AI Act compliance part 3: Roles and requirements for North American organizations</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EU AI Act compliance part 2: Understanding ‘high-risk’ activities</title>
		<link>https://www.dpocentre.ca/blog/eu-ai-act-compliance-high-risk-activities/</link>
		
		<dc:creator><![CDATA[Taylor Swann]]></dc:creator>
		<pubDate>Thu, 20 Mar 2025 17:34:41 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21827</guid>

					<description><![CDATA[<p>In the second part of our four-part guide to EU AI Act compliance for North American organizations, we explore the Act’s risk-based approach to classifying AI systems. What applications are prohibited, what constitutes ‘high-risk’ activity, and what systems are exempt?&#160; For details of the AI Act’s timeline and deadlines for its phased implementation, see Part [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/eu-ai-act-compliance-high-risk-activities/">EU AI Act compliance part 2: Understanding ‘high-risk’ activities</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In the second part of our four-part guide to EU AI Act compliance for North American organizations, we explore the Act’s risk-based approach to classifying AI systems. What applications are prohibited, what constitutes ‘high-risk’ activity, and what systems are exempt?&nbsp;</p>



<p class="wp-block-paragraph">For details of the AI Act’s timeline and deadlines for its phased implementation, see Part 1 of our blog series – <a href="https://www.dpocentre.ca/eu-ai-act-compliance-north-american-organizations/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/eu-ai-act-compliance-north-american-organizations/" rel="noreferrer noopener"><strong>EU AI Act compliance part 1: Timeline and important deadlines</strong>&nbsp;</a></p>



<h2 class="wp-block-heading"><br><strong>Understanding AI risk categories</strong></h2>



<p class="wp-block-paragraph">The EU AI Act’s risk-based approach to classifying AI systems aims to balance innovation with regulation to prevent harm to health, and ensure safety and fundamental human rights. By assessing risk, the legislation recognizes that not all AI systems pose the same level of threat and that varying levels of control and oversight are required.&nbsp;</p>



<p class="wp-block-paragraph">AI systems are categorized into different risk levels based on their potential impact, with the burden of compliance increasing proportionate to the risk.&nbsp;</p>



<p class="wp-block-paragraph">These are the three main categories:&nbsp;</p>



<ul class="wp-block-list">
<li>Prohibited&nbsp;</li>



<li>High risk&nbsp;</li>



<li>Low risk&nbsp;</li>
</ul>



<p class="wp-block-paragraph">For Canadian and US organizations, these categories apply to any AI systems that affect EU residents or markets, no matter where the system is developed or operated.&nbsp;</p>



<h4 class="wp-block-heading"><strong>Prohibited systems</strong></h4>



<p class="wp-block-paragraph">AI applications in this category are banned due to their unacceptable potential for negative consequences.&nbsp;</p>



<h4 class="wp-block-heading"><strong><strong>High-risk systems</strong></strong></h4>



<p class="wp-block-paragraph">These systems have a significant impact on people’s safety, wellbeing and rights, so are subject to stricter requirements. </p>



<h4 class="wp-block-heading"><strong><strong>Low-risk systems</strong></strong></h4>



<p class="wp-block-paragraph">These systems pose minimal dangers, so have fewer compliance obligations.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>AI applications prohibited by the Act</strong></h2>



<p class="wp-block-paragraph">The prohibitions on unacceptable risk AI systems came into force on February 1, 2025 (see the timeline of the phased implementation schedule <strong><a href="https://www.dpocentre.ca/eu-ai-act-compliance-north-american-organizations/" target="_blank" rel="noreferrer noopener">here</a></strong>).&nbsp;</p>



<p class="wp-block-paragraph">The European Commission will regularly review the list of prohibited AI applications, with the first review scheduled 12 months after the AI Act came into force.&nbsp;</p>



<p class="wp-block-paragraph">The table below details the types of AI practices that are the prohibited. These techniques and approaches pose unacceptable risks to health and safety or fundamental human rights, and while some of these practices may be permitted under North American regulations, they are prohibited when serving EU markets.&nbsp;</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>TYPES OF PROHIBITED AI PRACTICES</strong>&nbsp;</td><td><strong>DETAILS</strong>&nbsp;</td></tr><tr><td><strong>Subliminal, manipulative or deceptive</strong>&nbsp;</td><td>AI systems that use subliminal, manipulative or deceptive techniques to distort behavior and impair informed decision-making, causing significant harm&nbsp;<br>&nbsp;</td></tr><tr><td><strong>Exploitation of vulnerabilities</strong>&nbsp;</td><td>AI systems that exploit vulnerabilities related to a person’s age, disability, or socio-economic circumstances&nbsp;<br>&nbsp;</td></tr><tr><td><strong>Biometric categorization</strong>&nbsp;</td><td>AI applications that profile people based on certain sensitive characteristics (broadly aligned to GDPR special category data) such as race, political opinions, religious or philosophical beliefs, sexual orientation etc, subject to a narrow set of exceptions&nbsp;<br>&nbsp;</td></tr><tr><td><strong>Social scoring</strong>&nbsp;</td><td>AI systems that evaluate or classify individuals or groups based on social behavior or personal traits, which would cause detrimental or unfavorable treatment of those people&nbsp;<br>&nbsp;</td></tr><tr><td><strong>Risk assessment of individuals committing criminal offenses</strong>&nbsp;</td><td>AI systems used to assess the risk of an individual committing a crime, based solely on profiling or personality traits. Except when the system is used to strengthen and support human assessments based on objective and verifiable facts, directly linked to criminal activity&nbsp;<br>&nbsp;</td></tr><tr><td><strong>Large-scale facial recognition databases</strong>&nbsp;</td><td>AI systems using untargeted scraping of facial images from the internet or CCTV footage (with some limited exceptions for law enforcement)&nbsp;</td></tr><tr><td><strong>Inferring emotions in workplaces or educational institutions</strong>&nbsp;<br>&nbsp;</td><td>Except for AI systems used for medical or safety reasons&nbsp;<br>&nbsp;</td></tr><tr><td><strong>Real-time remote biometric identification (RBI) in public spaces</strong>&nbsp;</td><td>AI-enabled real-time RBI can only be used in certain situations and only allowed when not using the tool would cause considerable harm. Before deployment, police must conduct a fundamental rights impact assessment and register the system in the EU database&nbsp;<br>&nbsp;</td></tr></tbody></table></figure>



<h2 class="wp-block-heading"><br><strong><strong><strong>What constitutes ‘high-risk’ activity?</strong></strong></strong></h2>



<p class="wp-block-paragraph">Most of the AI Act addresses the regulation of high-risk AI systems, which fall into three distinct categories:</p>



<ul class="wp-block-list">
<li>Standalone AI products already covered by Union product safety laws&nbsp;</li>



<li>AI safety components&nbsp;</li>



<li>Designated ‘high-risk&#8217; categories&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Let’s explore these high-risk categories in a little more detail:&nbsp;</p>



<h4 class="wp-block-heading"><strong><strong>Standalone AI products&nbsp;</strong></strong></h4>



<p class="wp-block-paragraph">This refers to AI systems that are not a component or feature of a larger product, but rather the product in its entirety. Many of these types of products are already regulated by certain EU harmonization laws. Examples include medical devices, heavy industrial machinery, cars, and toys. These are listed in <strong><a href="https://artificialintelligenceact.eu/annex/1/" data-type="link" data-id="https://artificialintelligenceact.eu/annex/1/" target="_blank" rel="noreferrer noopener">Annex I of the AI Act</a></strong>.&nbsp;</p>



<p class="wp-block-paragraph">If you develop or deploy AI systems in a sector with tightly managed safety legislation, it’s highly likely the system will be covered here, and you should check the context of the Annex in full.&nbsp;</p>



<p class="wp-block-paragraph">As these products are already subject to strict safety regulations, they are automatically considered a high-risk category under the AI Act.&nbsp;</p>



<h4 class="wp-block-heading"><strong>AI safety components</strong></h4>



<p class="wp-block-paragraph">This means where an AI system isn’t a standalone product but performs safety-related functions within a product. For example, where an AI system is used for monitoring, controlling, or managing safety features.&nbsp;</p>



<p class="wp-block-paragraph">Many of these systems are related to products listed in Annex I of the AI Act, such as industrial machinery, lifts, medical devices, motor vehicles etc.&nbsp;</p>



<p class="wp-block-paragraph">The graphic below details the timeline, including some additional and earlier deadlines for specific provisions.&nbsp;</p>



<h3 class="wp-block-heading"><strong><strong><strong>Designated ‘high-risk’ categories</strong></strong></strong></h3>



<p class="wp-block-paragraph">Certain AI systems not listed in Annex I are also considered high risk.&nbsp;</p>



<p class="wp-block-paragraph">This defined list includes systems that would significantly impact people’s opportunities and potentially cause systemic bias against certain groups.&nbsp;</p>



<p class="wp-block-paragraph">These systems fall into 8 broad areas:&nbsp;</p>



<h4 class="wp-block-heading"><strong>Biometrics</strong>&nbsp;</h4>



<p class="wp-block-paragraph">Certain biometric processing is entirely prohibited, as detailed above, but all other biometric processing is classified as high risk (with the exception of ID verification of an individual for cybersecurity purposes – for example, Windows Hello and other biometric login systems used in North American workplaces).&nbsp;&nbsp;</p>



<h4 class="wp-block-heading"><strong>Critical infrastructure</strong><br>&nbsp;</h4>



<ul class="wp-block-list">
<li>AI systems used as safety components in managing critical digital infrastructure (similar to the list in Annex I) and utility systems – this applies to Canadian and US organizations providing services or infrastructure solutions to EU markets.&nbsp;&nbsp;</li>
</ul>



<h4 class="wp-block-heading"><strong>Education</strong>&nbsp;<br></h4>



<ul class="wp-block-list">
<li>Any AI system determining admissions or evaluating learning outcomes are high risk due to the potential impact on lives (including online learning platforms serving EU students), for example, the risk of perpetuating historic discrimination of women and ethnic minorities.&nbsp;&nbsp;</li>
</ul>



<h4 class="wp-block-heading"><strong>Employment &amp; management</strong>&nbsp;<br></h4>



<ul class="wp-block-list">
<li>Any AI system used for recruitment, job application analysis, and candidate evaluation are considered high risk (including North American companies hiring for EU operations or processing EU candidate data). Also, decision-making AI tools used for performance monitoring, work relationships, or termination of employment are high risk.&nbsp;&nbsp;</li>
</ul>



<h4 class="wp-block-heading"><strong>Access to essential services</strong>&nbsp;<br></h4>



<ul class="wp-block-list">
<li>Systems determining access to essential services such as public benefits like unemployment, disability and healthcare, or private benefits such as credit scoring systems. This includes Canadian and US financial institutions providing services to EU customers.&nbsp;</li>
</ul>



<h4 class="wp-block-heading"><strong>Law enforcement</strong><br></h4>



<ul class="wp-block-list">
<li>Certain tasks are considered high risk, including using lie detectors or similar biometric tools used for testimony assessment, and systems used to assess the likelihood of an individual reoffending. &nbsp;</li>
</ul>



<h4 class="wp-block-heading"><strong>Immigration</strong>&nbsp;<br></h4>



<ul class="wp-block-list">
<li>Systems used to assess the security risk of migrants entering the EU, or to process and evaluate asylum claims. AI systems used to verify ID documents are exempt from this.&nbsp;&nbsp;</li>
</ul>



<h4 class="wp-block-heading"><strong>Administration of justice and democratic processes</strong>&nbsp;<br></h4>



<ul class="wp-block-list">
<li>This includes AI systems used in legal research or interpreting the law, such as legal databases used by lawyers and judges. Also, systems that could influence voting, like those used to target political ads.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><br><strong>Exceptions to high-risk and prohibited AI systems</strong></h2>



<p class="wp-block-paragraph">The AI Act exempts certain AI systems otherwise considered high risk or prohibited.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Prohibited system exemptions </strong>are notably for research and national security.&nbsp;</p>



<p class="wp-block-paragraph"><strong>High-risk system exemptions </strong>can apply if<strong> </strong>the AI system:&nbsp;</p>



<ul class="wp-block-list">
<li>Performs only a narrow procedural task&nbsp;</li>



<li>Improves on the result of a previously completed human activity&nbsp;</li>



<li>Detects or monitors bias or other patterns in decision-making, but doesn’t replace human decision-making and is subject to human review&nbsp;</li>



<li>Is used for a preparatory task relevant to the assessment of an otherwise high-risk task i.e. you can use AI to help you assess your use case&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><br><strong>What this means for organizations using high-risk AI systems</strong></h2>



<p class="wp-block-paragraph">For Canadian and US organizations, this often means conducting additional risk assessments beyond those required by domestic regulations.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">High-risk AI systems supplied to the EU or affecting EU residents need thorough risk and security assessments and may need EU registration and third-party evaluation. There are also substantial transparency obligations, and users must be clearly informed about how an AI system is deployed and functions. For North American organizations operating globally, this may require maintaining different AI system configurations for EU and non-EU markets.&nbsp;</p>



<p class="wp-block-paragraph">If you need advice on ensuring your organization&#8217;s AI systems comply with EU requirements, while maintaining efficient operations across North American and European markets, please <strong><a href="https://www.dpocentre.ca/contact-us/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/contact-us/" rel="noreferrer noopener">contact our specialized DPO team</a></strong>.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>EU AI Act compliance part 3: Scope and obligations</strong></h2>



<p class="wp-block-paragraph">Coming next, in part 3 of our blog series, we cover the obligations of the AI Act in more detail, including who the AI Act applies to and what is required.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Don’t miss out on the latest data protection updates – stay informed with our fortnightly newsletter</strong>, <a href="https://www.dpocentre.ca/resources/thedpia/" data-type="link" data-id="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel="noreferrer noopener"><strong>The DPIA</strong></a>.</p>



<figure class="wp-block-image aligncenter size-large is-resized"><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="1024" height="536" src="https://www.dpocentre.ca/wp-content/uploads/2025/03/DPIA-sign-up-advert-1024x536.jpg" alt="DPIA sign up advert" class="wp-image-21828" style="width:600px" title="EU AI Act compliance part 2: Understanding ‘high-risk’ activities 7"></a></figure>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><a href="https://www.dpocentre.ca/eu-ai-act-compliance-north-american-organizations/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/privacy-in-canada-usa-2024-and-2025-expectations/" rel="noreferrer noopener"><strong>EU AI Act compliance part 1: Timeline and important deadlines</strong>&nbsp;</a></li>



<li><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/" data-type="link" data-id="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses/"><strong>How GDPR territorial scope impacts North American businesses</strong>&nbsp;</a></li>



<li><a href="https://www.dpocentre.ca/gdpr-guide-for-saas-companies-eu-uk/" target="_blank" rel="noreferrer noopener"><strong>GDPR advise for SaaS companies expanding into EU and UK markets</strong>&nbsp;</a></li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong>For more news and insights about data protection follow The DPO Centre on&nbsp;<a href="https://uk.linkedin.com/company/dpo-centre" target="_blank" rel="noreferrer noopener">LinkedIn</a></strong></p>



<p class="wp-block-paragraph"></p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/eu-ai-act-compliance-high-risk-activities/">EU AI Act compliance part 2: Understanding ‘high-risk’ activities</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EU AI Act compliance: What North American organizations need to know </title>
		<link>https://www.dpocentre.ca/blog/eu-ai-act-compliance-north-american-organizations/</link>
		
		<dc:creator><![CDATA[Taylor Swann]]></dc:creator>
		<pubDate>Thu, 27 Feb 2025 15:54:04 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://www.dpocentre.ca/?p=21792</guid>

					<description><![CDATA[<p>Our four-part guide to EU AI Act compliance explores what North American organizations need to know about the upcoming legal obligations when rolling out certain artificial intelligence (AI) technologies under the EU’s landmark AI Act.&#160; If your organization operates in or serves EU markets and has AI-driven chatbots to handle customer inquiries, develops predictive algorithms [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/eu-ai-act-compliance-north-american-organizations/">EU AI Act compliance: What North American organizations need to know </a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Our four-part guide to </em><strong><em>EU AI Act compliance </em></strong><em>explores what North American organizations need to know about the upcoming legal obligations when rolling out certain artificial intelligence (AI) technologies under the EU’s landmark AI Act.</em>&nbsp;</p>



<p class="wp-block-paragraph">If your organization operates in or serves EU markets and has AI-driven chatbots to handle customer inquiries, develops predictive algorithms for credit risk, or uses image recognition software, the EU’s AI Act may impact how you handle data.&nbsp;</p>



<p class="wp-block-paragraph">Understanding the requirements of the AI Act and what will apply to your organization is crucial for compliance.&nbsp;</p>



<p class="wp-block-paragraph">In our four-part blog series, we cover:&nbsp;</p>



<ol start="1" class="wp-block-list">
<li>Timeline and deadlines&nbsp;</li>



<li>What constitutes a high-risk activity?&nbsp;</li>



<li>Who has to comply with the AI Act?&nbsp;</li>



<li>Strategies for achieving AI Act compliance&nbsp;</li>
</ol>



<h2 class="wp-block-heading"><strong>EU AI Act compliance part 1: Timeline and important deadlines</strong></h2>



<p class="wp-block-paragraph">The AI Act was approved by the European Council in May 2024. It has a phased implementation schedule over two years, designed to give organizations time to make the necessary changes for compliance.&nbsp;</p>



<p class="wp-block-paragraph">The new legislation applies to public and private organizations operating in the EU that develop, deploy, or use AI systems in the EU’s single market. For North American organizations, this includes companies doing business in the EU or providing AI-powered services to EU customers, as well as institutions, government bodies, research organizations and any others involved in AI-related activities that impact EU markets.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong><strong>How the AI Act and the GDPR work together</strong>&nbsp;</strong></h2>



<p class="wp-block-paragraph">David Smith, DPO and AI Sector Lead explains:&nbsp;</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><em>‘In many cases the AI Act and the GDPR will complement each other. The AI Act is essentially a product safety legislation designed to ensure the responsible and non-harmful deployment of AI systems. The GDPR is a principles-based law, protecting fundamental human privacy rights.’</em>&nbsp;</p>
</blockquote>



<h3 class="wp-block-heading"><strong>When did the AI Act come into force?</strong></h3>



<p class="wp-block-paragraph">The AI Act’s finalized text was published in the Official Journal of the European Union on July 12, 2024. It officially entered into force 20 days after publication on August 1, 2024, with the enforcement of most of its provisions starting on August 2, 2026.&nbsp;</p>



<p class="wp-block-paragraph">The graphic below details the timeline, including some additional and earlier deadlines for specific provisions.&nbsp;</p>



<figure class="wp-block-image aligncenter size-large"><img loading="lazy" decoding="async" width="1018" height="1024" src="https://www.dpocentre.ca/wp-content/uploads/2025/02/1.5-Compliance-with-the-AI-Act-What-you-need-to-know-graphic-1-1018x1024.png" alt=" EU AI Act timeline and critical deadlines" class="wp-image-21793" title="EU AI Act compliance: What North American organizations need to know  8" srcset="https://www.dpocentre.ca/wp-content/uploads/2025/02/1.5-Compliance-with-the-AI-Act-What-you-need-to-know-graphic-1-1018x1024.png 1018w, https://www.dpocentre.ca/wp-content/uploads/2025/02/1.5-Compliance-with-the-AI-Act-What-you-need-to-know-graphic-1-298x300.png 298w, https://www.dpocentre.ca/wp-content/uploads/2025/02/1.5-Compliance-with-the-AI-Act-What-you-need-to-know-graphic-1-150x150.png 150w, https://www.dpocentre.ca/wp-content/uploads/2025/02/1.5-Compliance-with-the-AI-Act-What-you-need-to-know-graphic-1-768x773.png 768w, https://www.dpocentre.ca/wp-content/uploads/2025/02/1.5-Compliance-with-the-AI-Act-What-you-need-to-know-graphic-1-1526x1536.png 1526w, https://www.dpocentre.ca/wp-content/uploads/2025/02/1.5-Compliance-with-the-AI-Act-What-you-need-to-know-graphic-1.png 1920w" sizes="(max-width: 1018px) 100vw, 1018px" /></figure>



<h3 class="wp-block-heading"><strong><strong>August 1, 2024: The AI Act becomes law</strong></strong></h3>



<h4 class="wp-block-heading"><br><strong>February 1, 2025 (+6 months)</strong></h4>



<p class="wp-block-paragraph">Prohibitions on unacceptable risk AI systems apply six months after the AI Act became law.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Banned AI practices are those deemed to pose unacceptable risks to health and safety or fundamental human rights. We will cover prohibited AI applications in more detail in our next blog.&nbsp;</p>



<p class="wp-block-paragraph">With the deadline for compliance on unacceptable risk AI systems already past, organizations should evaluate their risk exposure in this area urgently if they haven’t yet done so.&nbsp;</p>



<h3 class="wp-block-heading"><strong><strong>May 1, 2025 (+9 months)</strong></strong></h3>



<p class="wp-block-paragraph">The AI Office will finalize the codes of conduct to cover the obligations for developers and deployers of AI systems. These codes will provide voluntary guidelines for responsible AI development and use.&nbsp;</p>



<h3 class="wp-block-heading"><strong><strong>August 1, 2025 (+12 months)</strong></strong></h3>



<p class="wp-block-paragraph">The rules for providers of General Purpose AI (GPAI) will come into effect and organizations will need to align their practices with these new rules. GPAI refers to advanced AI systems that can perform a wide range of tasks. These include high-compute models where training contains more than 10^25 FLOPS, such as ChatGPT.&nbsp;</p>



<p class="wp-block-paragraph">In addition, the first European Commission annual review of the list of prohibited AI applications will happen 12 months after the AI Act enters into force.&nbsp;</p>



<h3 class="wp-block-heading"><strong><strong>February 1, 2026 (+18 months)</strong></strong></h3>



<p class="wp-block-paragraph">The European Commission will issue implementing acts for high-risk AI providers. This means organizations using high-risk AI systems must follow a standard template to monitor the AI systems after deployment.&nbsp;</p>



<p class="wp-block-paragraph">The monitoring plan will help to identify and address any issues or risks, promptly.&nbsp;</p>



<h3 class="wp-block-heading"><strong>August 1, 2026 (+24 months)</strong></h3>



<p class="wp-block-paragraph">The remainder of the AI Act will apply, including regulations on high-risk AI systems listed in Annex III* of the AI Act. These systems include those related to biometrics and cover technologies such as fingerprint recognition, facial recognition, iris scanning and voice authentication.&nbsp;</p>



<p class="wp-block-paragraph">We cover high-risk AI systems in more detail in our next blog.&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://artificialintelligenceact.eu/annex/3/" target="_blank" data-type="link" data-id="https://artificialintelligenceact.eu/annex/3/" rel="noreferrer noopener"><strong>EU Artificial Intelligence Act Annex III&nbsp;</strong></a></p>



<h3 class="wp-block-heading"><strong>August 1, 2027 (+36 months)</strong></h3>



<p class="wp-block-paragraph">Regulations for high-risk AI systems stipulated in Annex I** become effective.&nbsp;</p>



<p class="wp-block-paragraph"><strong><a href="https://artificialintelligenceact.eu/annex/1/" target="_blank" data-type="link" data-id="https://artificialintelligenceact.eu/annex/1/" rel="noreferrer noopener">EU Artificial Intelligence Act Annex I</a></strong></p>



<h3 class="wp-block-heading"><strong>By the end of 2030</strong></h3>



<p class="wp-block-paragraph">There are some minor exceptions for certain complex public sector systems that have a longer compliance timeline.&nbsp;</p>



<h2 class="wp-block-heading"><br><strong>Coming up next&#8230;</strong></h2>



<h2 class="wp-block-heading"><br><strong>EU AI Act compliance part 2: What is ‘high-risk’ activity?</strong></h2>



<p class="wp-block-paragraph">Stay tuned for the second blog in our four-part series, which covers all you need to know about prohibited AI applications and what is categorized as a high-risk activity – stay tuned!&nbsp;</p>



<p class="wp-block-paragraph">In the meantime, should you require any advice on EU or UK jurisdiction data protection, our team of expert DPOs can help. We offer a wide range of outsourced privacy services, including AI Governance support for North American organizations operating in EU markets. <a href="https://www.dpocentre.ca/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/" rel="noreferrer noopener"><strong>CONTACT US</strong>&nbsp;</a></p>



<p class="wp-block-paragraph">For more privacy updates and breaking news, <a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/resources/thedpia/" rel="noreferrer noopener"><strong>sign up to our fortnightly newsletter.&nbsp;</strong></a></p>



<figure class="wp-block-image aligncenter"><a href="https://www.dpocentre.ca/resources/thedpia/" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="600" height="314" src="https://www.dpocentre.ca/wp-content/uploads/2025/02/The-DPIA-Newsletter_-1-e1740571691621.png" alt="The DPIA Newsletter_" class="wp-image-21795" title="EU AI Act compliance: What North American organizations need to know  9"></a></figure>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<h3 class="wp-block-heading"><strong>In case you missed it…</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li><a href="https://www.dpocentre.ca/gdpr-territorial-scope-north-american-businesses" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/privacy-in-canada-usa-2024-and-2025-expectations/" rel="noreferrer noopener"><strong>How GDPR territorial scope impacts North American businesses</strong>&nbsp;</a></li>



<li><a href="https://www.dpocentre.ca/gdpr-guide-for-saas-companies-eu-uk/" target="_blank" rel="noreferrer noopener"><strong>GDPR advise for SaaS companies expanding into EU and UK markets</strong>&nbsp;</a></li>



<li><a href="https://www.dpocentre.ca/gdpr-representative-do-you-need-one/" target="_blank" data-type="link" data-id="https://www.dpocentre.ca/gdpr-representative-do-you-need-one/" rel="noreferrer noopener"><strong>GDPR Representative: Do you need one?</strong>&nbsp;</a></li>
</ul>



<p class="wp-block-paragraph">____________________________________________________________________________________________________________</p>



<p class="wp-block-paragraph"><strong>For more news and insights about data protection follow The DPO Centre on&nbsp;<a href="https://uk.linkedin.com/company/dpo-centre" target="_blank" rel="noreferrer noopener">LinkedIn</a></strong></p>



<p class="wp-block-paragraph"></p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/eu-ai-act-compliance-north-american-organizations/">EU AI Act compliance: What North American organizations need to know </a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Data Protection in 2023: A year in review</title>
		<link>https://www.dpocentre.ca/blog/data-protection-in-2023-a-year-in-review/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Fri, 22 Dec 2023 22:22:34 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Global data privacy laws]]></category>
		<category><![CDATA[International data transfers]]></category>
		<guid isPermaLink="false">https://dpoca.server.terryh.uk/?p=20821</guid>

					<description><![CDATA[<p>This year has seen significant progress in the data protection industry, with many new privacy laws being enacted across the globe. In this blog, we look at some of the major events and news stories that have shaped the landscape, influencing the direction of policies and processes. What does the development of data protection laws [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/data-protection-in-2023-a-year-in-review/">Data Protection in 2023: A year in review</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This year has seen significant progress in the data protection industry, with many new privacy laws being enacted across the globe.</p>



<p class="wp-block-paragraph">In this blog, we look at some of the major events and news stories that have shaped the landscape, influencing the direction of policies and processes.</p>



<p class="wp-block-paragraph">What does the development of data protection laws mean for organisations? And how will the data protection industry continue to evolve? Big questions to keep in mind as we go into 2024.</p>



<h2 class="wp-block-heading"><strong>Major data protection events</strong></h2>



<p class="wp-block-paragraph"><strong>5 years of the GDPR:</strong>&nbsp;The General Data Protection Regulation (GDPR) celebrated its 5<sup>th</sup>&nbsp;anniversary on 25 May 2023. Coming into force on 25 May 2018, it is cited as one of the toughest pieces of privacy legislation in the world. The EU’s principle-based directive was introduced to protect the fundamental rights of individuals by safeguarding their personal data and creating a harmonised framework for data flow across the EU’s digital single market.</p>



<p class="wp-block-paragraph">To mark the anniversary, The DPO Centre held a webinar to discuss the wins and challenges for businesses. Essentially, what worked, what didn’t, and why?&nbsp;<a href="https://www.dpocentre.com/resources/gdpr-webinar/" target="_blank" rel="noreferrer noopener"><strong>Watch The DPO Centre’s lively GDPR debate here</strong></a></p>



<p class="wp-block-paragraph"><strong>Facebook fined a record €1.2 billion:&nbsp;</strong>On 22 May 2023, after 10 years of litigation and 3 court procedures, the Irish Data Protection Commission issued Meta Ireland with the largest GDPR fine to date. It was the fourth fine Meta received this year. The Commission issued two penalties in January 2023 for breaching rules with targeted ads on Facebook and Instagram and in March 2023, a fine for GDPR breaches with WhatsApp.</p>



<p class="wp-block-paragraph">The fines sent a strong message to Tech giants that they cannot continue to neglect their obligations for compliance with data protections regulations. However, Meta has yet to pay the fine and announced its intention to appeal. One of the orders of the penalty charge was for Meta to discontinue its reliance on Standard Contractual Clauses (SCCs) by 12 October. In an update on 7 September 2023, Meta announced they will rely on the new EU-US DPF for data transfers.</p>



<p class="wp-block-paragraph"><strong>The AI Safety Summit</strong>&nbsp;took place in the UK on 1 November 2023 at Bletchley Park. Intended as a landmark event for artificial intelligence, the event brought together leading experts, researchers, and policymakers from around the world.</p>



<p class="wp-block-paragraph">An important outcome of the Summit was&nbsp;<strong>The Bletchley Declaration</strong>&nbsp;– a world-first agreement between 28 jurisdictions, including the EU, the US, and China. The Declaration establishes a shared responsibility to understand and manage the potential risks of AI development. Bias and privacy are topics covered within the Declaration, providing an agenda to focus on building respective risk-based policies across the countries. However, critics have highlighted the lack of detail and the absence of any actionable points for building an effective regulatory framework.</p>



<h2 class="wp-block-heading"><strong>Data protection developments in the EU, UK, and North America</strong></h2>



<p class="wp-block-paragraph"><strong>Europe’s GDPR continues to mature</strong></p>



<p class="wp-block-paragraph">Since its implementation in 2018, the General Data Protection Regulation (GDPR) has become a global standard for data protection. With each passing year, we see further clarification on its interpretation, and a greater understanding of the implications for businesses and individuals alike.</p>



<p class="wp-block-paragraph">There were several key court rulings by the Court of Justice of the European Union (CJEU) this year, which have helped to clarify certain areas of the legislation:</p>



<ul class="wp-block-list">
<li>Accountability principle – The CJEU ruled that not every violation of the GDPR would render all related processing to be unlawful (<a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;docid=273289&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=3199198" target="_blank" rel="noreferrer noopener"><strong>Case C-60/22</strong></a>)</li>



<li>Right of Access – The CJEU clarified the scope of the GDPR right of access by stating that the right to obtain a ‘copy’ of personal data means that the data subject must be given a ‘faithful and intelligible’ reproduction of all those data</li>



<li>Joint Controllers – The CJEU stated that if a company doesn’t follow GDPR rules for making a joint controller agreement or keeping records of data processing activities, it doesn’t automatically mean that the company’s data processing is illegal.</li>



<li>Penalty fines – The CJEU ruled on 5 December 2023 that a supervisory Data Protection Authority (DPA) may only impose a fine for a GDPR infringement if it was committed wrongfully, either intentionally or negligently. In calculating a fine, a DPA must consider the total worldwide turnover of the entire group from the preceding business year.</li>
</ul>



<p class="wp-block-paragraph"><strong>The European Commission adopted its adequacy decision on EU-US data flows&nbsp;</strong>and established the EU-US Data Privacy Framework (DPF), which came into effect on 10 July 2023. The DPF replaced the invalidated Privacy Shield and aimed to address the concerns previously raised by the CJEU. However, only minutes after the announcement, Max Schrems, Austrian privacy lawyer and activist, expressed his scepticism of the decision and stated his intention to challenge the new deal. A challenge has yet to be submitted by Mr Schrems, but the debate over transatlantic data transfers is clearly not over and will continue into 2024.&nbsp;<strong><a href="https://www.dpocentre.com/eu-us-data-privacy-framework-3rd-time-lucky/" target="_blank" rel="noreferrer noopener">Learn more about the EU-US DPF</a></strong></p>



<h2 class="wp-block-heading"><strong>UK’s key data protection updates</strong></h2>



<p class="wp-block-paragraph"><strong>The UK-US ‘data-bridge’</strong>&nbsp;was approved on 21 September 2023, with it coming into force on 12 October 2023. Serving as an extension to the EU’s Data Privacy Framework (DPF), the data-bridge provides a mechanism for businesses in the UK to transfer personal data to US organisations certified under the ‘UK Extension to the EU-US Data Privacy Framework’ (UK Extension) without the need for further safeguards. However, criticisms of the EU-US DPF include concerns over the potential for increased surveillance by US authorities and the erosion of privacy rights. Many organisations have retained their existing data transfer mechanisms with a ‘wait and see’ approach.</p>



<p class="wp-block-paragraph"><strong>DSIT published AI Skills for Business Competency Framework&nbsp;</strong>for public consultation in November 2023. Supported by the Office for Artificial Intelligence within the Department for Science, Innovation and Technology (DSIT), the draft framework presents guidance on the essential knowledge, skills, and behaviours employees should have to benefit from AI technology. DSIT intends the framework to support businesses, enabling them to understand their AI upskilling needs and to assist training providers in developing relevant training solutions.&nbsp;<a href="https://iuk.ktn-uk.org/wp-content/uploads/2023/11/Final_BridgeAI_Framework.pdf" target="_blank" rel="noreferrer noopener"><strong>Read the draft AI Skills for Business framework</strong></a></p>



<p class="wp-block-paragraph"><strong>The UK’s proposed GDPR replacement moves closer</strong></p>



<p class="wp-block-paragraph">On 19 December 2023 the Data Protection and Digital Information (DPDI) Bill was debated at the second reading stage in the House of Lords. The government believes the updates to the current UK GDPR will support innovation and reduce unnecessary burdens on businesses and organisations. However, the new legislation has the potential to increase costs and complexities for all but the smallest of businesses.</p>



<p class="wp-block-paragraph">The Lords raised many concerns during the second reading, with Lord Bishop of Southwell and Nottingham quoting Rob Masson of The DPO Centre. The Lord Bishop used Mr Masson’s words when calling attention to the way in which the UK seems to be going in the opposite direction to the rest of the globe by lowering data protection standards.</p>



<p class="wp-block-paragraph">Lord Allan of Hallam said,&nbsp;<em>‘It is the concern around EU adequacy that I think should really be front and centre of our discussions when we consider this legislation.’</em></p>



<p class="wp-block-paragraph">This concern was echoed by several other Members, with Lord Vaux of Harrowden succinctly stating,&nbsp;<em>‘We must get this Bill right. If we do not, we risk substantial damage to the economy, businesses, individuals’’ privacy rights – especially children – and even, as far as the surveillance elements go, to our status as a free and open democratic society.’<br></em><a href="https://www.dpocentre.com/dpdi/" target="_blank" rel="noreferrer noopener"><strong>Read the key differences between the UK GDPR and DPDI</strong></a></p>



<h2 class="wp-block-heading"><strong>Canada seeks to update and strengthen its privacy laws</strong></h2>



<p class="wp-block-paragraph">There have been significant developments in Canada’s privacy laws this year. On 24 April, the Canadian House of Commons agreed on the entirety of Bill C-27, the Digital Charter Implementation Act 2022, which seeks to update and strengthen the Personal Information Protection and Electronic Documents Act (PIPEDA), including Canada’s first AI legislation.</p>



<p class="wp-block-paragraph"><strong>In Quebec</strong>, ‘An Act to modernise legislative provisions as regards the protection of personal information’ came into effect in 22 September 2023, with the right to portability under this Act is due to come into force on 22 September 2024.<br><a href="https://www.canlii.org/en/qc/laws/astat/sq-2021-c-25/latest/sq-2021-c-25.pdf" target="_blank" rel="noreferrer noopener"><strong>Read the PDF of Bill 64</strong>&nbsp;</a></p>



<h2 class="wp-block-heading"><strong>The United States sees a wave of new privacy laws</strong></h2>



<p class="wp-block-paragraph">It was a big year for privacy in the US, with 5 new state privacy laws:</p>



<ul class="wp-block-list">
<li>California Privacy Rights Act (CPRA) came into effect on 1 January 2023 and amends the California Consumer Privacy Act (CCPA)</li>



<li>Virginia Consumer Data Protection Act (VCDPA) came into effect on 1 January 2023</li>



<li>The Colorado Privacy Act (CPA) came into effect on 1 July 2023</li>



<li>The Connecticut Data Privacy Act (CTDPA) came into effect on 1 July 2023</li>



<li>The Utah Consumer Privacy Act (UCPA) will come into effect on 31 December 2023</li>
</ul>



<p class="wp-block-paragraph">These laws reflect a shift towards greater consumer control over personal data and increased obligations for organisations in terms of data processing. They also indicate a move towards harmonising state-level laws with global standards, providing new consumer rights aligned with those in the GDPR.</p>



<h2 class="wp-block-heading"><strong>Looking ahead: Data protection in 2024</strong></h2>



<p class="wp-block-paragraph"><a href="https://thedpia.com/" target="_blank" rel="noreferrer noopener"><strong>Subscribe to The DPIA</strong></a>&nbsp;– Keep updated on the latest, most important data protection news with our fortnightly email newsletter.</p>



<p class="wp-block-paragraph"><strong>UK’s DPDI Bill</strong></p>



<p class="wp-block-paragraph">As we move into 2024, all eyes are carefully watching the progress of the proposed Data Protection and Digital Information (DPDI) Bill. The hope of the data protection industry is that the Lords will take into consideration their numerous concerns and apply rigorous scrutiny to the proposed legislation. But only time will tell. We will keep you updated soon as we have further information.</p>



<p class="wp-block-paragraph"><strong>3<sup>rd</sup>&nbsp;party cookies in Chrome to be disabled</strong></p>



<p class="wp-block-paragraph">Google’s plan to phase out 3<sup>rd</sup>&nbsp;party cookies in its Chrome browser begins in quarter 1 of 2024. This is part of a larger initiative called the&nbsp;<strong><a href="https://privacysandbox.com/" target="_blank" rel="noreferrer noopener">Privacy Sandbox</a></strong>&nbsp;project, which aims to reduce cross-site tracking whilst still allowing functionality to keep online services and content freely available.</p>



<p class="wp-block-paragraph">Google will disable 3<sup>rd</sup>&nbsp;party cookies for 1% of users from early January, applying the changes to 100% of users by Q3 2024. The full rollout depends on Google addressing the competition concerns of the UK’s Competition and Markets Authority (CMA). The phasing out of non-essential cookies is in line with the wider global trend towards enhanced data protection and privacy.</p>



<p class="wp-block-paragraph"><a href="https://digital-strategy.ec.europa.eu/en/policies/eprivacy-regulation" target="_blank" rel="noreferrer noopener"><strong>The EU’s</strong>&nbsp;<strong>proposed ePrivacy Regulation</strong></a>&nbsp;establishes clearer rules on cookies, with a more streamlined solution for settings:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><em>‘no consent is needed for non-privacy intrusive cookies that improve internet experience, such as cookies to remember shopping-cart history or to count the number of website visitors.’ (Proposal for an ePrivacy Regulation)</em></p>
</blockquote>



<p class="wp-block-paragraph"><strong>International data transfers</strong></p>



<p class="wp-block-paragraph"><strong>SCCs and IDTA</strong>&nbsp;– From 21 March 2024, UK organisations can no longer use the old EU Standard Contractual Clauses (SCCs) for restricted data transfers. Instead, they must rely on the UK’s International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum (‘UK Addendum’).</p>



<p class="wp-block-paragraph"><strong>EU-UK adequacy</strong>&nbsp;– Later in 2024, the European Commission is due to review the EU-UK adequacy, which will expire on 27 June 2025. The outcome of the UK’s proposed DPDI Bill could significantly affect this decision and create further complications for organisations operating across multiple jurisdictions.</p>



<p class="wp-block-paragraph"><strong>EDPB action: Right of access by controllers</strong></p>



<p class="wp-block-paragraph">The European Data Protection Board (EDPB) will launch a national action in 2024 on ‘The right of access by controllers’. Each year, the EDPB seeks to prioritise certain topics for data protection authorities (DPAs) to work on at a national level. This will be the third co-ordinated enforcement action to date. The results allow for analysis and insight into the topic, which allows for targeted follow-up at both national and EU levels.</p>



<p class="wp-block-paragraph"><strong>The EU’s AI Act</strong></p>



<p class="wp-block-paragraph">With European Parliamentary Elections scheduled for 6-9 June 2024, the EU is likely to adopt the proposed AI Act in early 2024. Otherwise, the elections could delay its passage until 2025. The Act has seen a certain amount of progress in 2023, with the European Parliament adopting amendments to the proposal on 14 June 2023. However, there have been stumbling blocks, especially over the way generative AI platforms like ChatGPT should be regulated. Big Tech companies have been lobbying to weaken the proposed EU legislation and there have also been calls from the French, German, and Italian governments to reduce some of the stringent measures to ensure AI innovation.</p>



<p class="wp-block-paragraph"><strong>The UK’s AI Regulation Bill</strong></p>



<p class="wp-block-paragraph">The AI Regulation Bill is a Private Member’s Bill, originating in the House of Lords during the 2023-24 session. Last updated on 29 November 2023, the Bill includes provisions for the creation of a body called the AI Authority and the appointment of designated AI officers. The government intends to publish a draft AI risk register for consultation, an updated AI regulatory roadmap, and a monitoring and evaluation report after March 2024.</p>



<h2 class="wp-block-heading"><strong>Data Protection support and advice for 2024</strong></h2>



<p class="wp-block-paragraph">Data protection and privacy is a rapidly evolving industry. The pace of change is a challenge for organisations across all sectors, with new laws and new guidance being released regularly. The ever-pressing need for professional advice and guidance from data protection experts looks set to increase as we move into 2024.</p>



<p class="wp-block-paragraph"><strong>The DPO Centre</strong> offers a range of data protection services, including consultancy, outsourced Data Protection Officers (DPOs), GDPR Representatives and AI Explainability (XAI) Services.</p>



<p class="wp-block-paragraph">This year has seen significant progress in the data protection industry, with many new privacy laws being enacted across the globe.</p>



<p class="wp-block-paragraph">In this blog, we look at some of the major events and news stories that have shaped the landscape, influencing the direction of policies and processes.</p>



<p class="wp-block-paragraph">What does the development of data protection laws mean for organisations? And how will the data protection industry continue to evolve? Big questions to keep in mind as we go into 2024.</p>



<h2 class="wp-block-heading"><strong>Major data protection events</strong></h2>



<p class="wp-block-paragraph"><strong>5 years of the GDPR:</strong>&nbsp;The General Data Protection Regulation (GDPR) celebrated its 5<sup>th</sup>&nbsp;anniversary on 25 May 2023. Coming into force on 25 May 2018, it is cited as one of the toughest pieces of privacy legislation in the world. The EU’s principle-based directive was introduced to protect the fundamental rights of individuals by safeguarding their personal data and creating a harmonised framework for data flow across the EU’s digital single market.</p>



<p class="wp-block-paragraph">To mark the anniversary, The DPO Centre held a webinar to discuss the wins and challenges for businesses. Essentially, what worked, what didn’t, and why?&nbsp;<a href="https://www.dpocentre.com/resources/gdpr-webinar/" target="_blank" rel="noreferrer noopener"><strong>Watch The DPO Centre’s lively GDPR debate here</strong></a></p>



<p class="wp-block-paragraph"><strong>Facebook fined a record €1.2 billion:&nbsp;</strong>On 22 May 2023, after 10 years of litigation and 3 court procedures, the Irish Data Protection Commission issued Meta Ireland with the largest GDPR fine to date. It was the fourth fine Meta received this year. The Commission issued two penalties in January 2023 for breaching rules with targeted ads on Facebook and Instagram and in March 2023, a fine for GDPR breaches with WhatsApp.</p>



<p class="wp-block-paragraph">The fines sent a strong message to Tech giants that they cannot continue to neglect their obligations for compliance with data protections regulations. However, Meta has yet to pay the fine and announced its intention to appeal. One of the orders of the penalty charge was for Meta to discontinue its reliance on Standard Contractual Clauses (SCCs) by 12 October. In an update on 7 September 2023, Meta announced they will rely on the new EU-US DPF for data transfers.</p>



<p class="wp-block-paragraph"><strong>The AI Safety Summit</strong>&nbsp;took place in the UK on 1 November 2023 at Bletchley Park. Intended as a landmark event for artificial intelligence, the event brought together leading experts, researchers, and policymakers from around the world.</p>



<p class="wp-block-paragraph">An important outcome of the Summit was&nbsp;<strong>The Bletchley Declaration</strong>&nbsp;– a world-first agreement between 28 jurisdictions, including the EU, the US, and China. The Declaration establishes a shared responsibility to understand and manage the potential risks of AI development. Bias and privacy are topics covered within the Declaration, providing an agenda to focus on building respective risk-based policies across the countries. However, critics have highlighted the lack of detail and the absence of any actionable points for building an effective regulatory framework.</p>



<h2 class="wp-block-heading"><strong>Data protection developments in the EU, UK, and North America</strong></h2>



<p class="wp-block-paragraph"><strong>Europe’s GDPR continues to mature</strong></p>



<p class="wp-block-paragraph">Since its implementation in 2018, the General Data Protection Regulation (GDPR) has become a global standard for data protection. With each passing year, we see further clarification on its interpretation, and a greater understanding of the implications for businesses and individuals alike.</p>



<p class="wp-block-paragraph">There were several key court rulings by the Court of Justice of the European Union (CJEU) this year, which have helped to clarify certain areas of the legislation:</p>



<ul class="wp-block-list">
<li>Accountability principle – The CJEU ruled that not every violation of the GDPR would render all related processing to be unlawful (<a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;docid=273289&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=3199198" target="_blank" rel="noreferrer noopener"><strong>Case C-60/22</strong></a>)</li>



<li>Right of Access – The CJEU clarified the scope of the GDPR right of access by stating that the right to obtain a ‘copy’ of personal data means that the data subject must be given a ‘faithful and intelligible’ reproduction of all those data</li>



<li>Joint Controllers – The CJEU stated that if a company doesn’t follow GDPR rules for making a joint controller agreement or keeping records of data processing activities, it doesn’t automatically mean that the company’s data processing is illegal.</li>



<li>Penalty fines – The CJEU ruled on 5 December 2023 that a supervisory Data Protection Authority (DPA) may only impose a fine for a GDPR infringement if it was committed wrongfully, either intentionally or negligently. In calculating a fine, a DPA must consider the total worldwide turnover of the entire group from the preceding business year.</li>
</ul>



<p class="wp-block-paragraph"><strong>The European Commission adopted its adequacy decision on EU-US data flows&nbsp;</strong>and established the EU-US Data Privacy Framework (DPF), which came into effect on 10 July 2023. The DPF replaced the invalidated Privacy Shield and aimed to address the concerns previously raised by the CJEU. However, only minutes after the announcement, Max Schrems, Austrian privacy lawyer and activist, expressed his scepticism of the decision and stated his intention to challenge the new deal. A challenge has yet to be submitted by Mr Schrems, but the debate over transatlantic data transfers is clearly not over and will continue into 2024.&nbsp;<strong><a href="https://www.dpocentre.com/eu-us-data-privacy-framework-3rd-time-lucky/" target="_blank" rel="noreferrer noopener">Learn more about the EU-US DPF</a></strong></p>



<h2 class="wp-block-heading"><strong>UK’s key data protection updates</strong></h2>



<p class="wp-block-paragraph"><strong>The UK-US ‘data-bridge’</strong>&nbsp;was approved on 21 September 2023, with it coming into force on 12 October 2023. Serving as an extension to the EU’s Data Privacy Framework (DPF), the data-bridge provides a mechanism for businesses in the UK to transfer personal data to US organisations certified under the ‘UK Extension to the EU-US Data Privacy Framework’ (UK Extension) without the need for further safeguards. However, criticisms of the EU-US DPF include concerns over the potential for increased surveillance by US authorities and the erosion of privacy rights. Many organisations have retained their existing data transfer mechanisms with a ‘wait and see’ approach.</p>



<p class="wp-block-paragraph"><strong>DSIT published AI Skills for Business Competency Framework&nbsp;</strong>for public consultation in November 2023. Supported by the Office for Artificial Intelligence within the Department for Science, Innovation and Technology (DSIT), the draft framework presents guidance on the essential knowledge, skills, and behaviours employees should have to benefit from AI technology. DSIT intends the framework to support businesses, enabling them to understand their AI upskilling needs and to assist training providers in developing relevant training solutions.&nbsp;<a href="https://iuk.ktn-uk.org/wp-content/uploads/2023/11/Final_BridgeAI_Framework.pdf" target="_blank" rel="noreferrer noopener"><strong>Read the draft AI Skills for Business framework</strong></a></p>



<p class="wp-block-paragraph"><strong>The UK’s proposed GDPR replacement moves closer</strong></p>



<p class="wp-block-paragraph">On 19 December 2023 the Data Protection and Digital Information (DPDI) Bill was debated at the second reading stage in the House of Lords. The government believes the updates to the current UK GDPR will support innovation and reduce unnecessary burdens on businesses and organisations. However, the new legislation has the potential to increase costs and complexities for all but the smallest of businesses.</p>



<p class="wp-block-paragraph">The Lords raised many concerns during the second reading, with Lord Bishop of Southwell and Nottingham quoting Rob Masson of The DPO Centre. The Lord Bishop used Mr Masson’s words when calling attention to the way in which the UK seems to be going in the opposite direction to the rest of the globe by lowering data protection standards.</p>



<p class="wp-block-paragraph">Lord Allan of Hallam said,&nbsp;<em>‘It is the concern around EU adequacy that I think should really be front and centre of our discussions when we consider this legislation.’</em></p>



<p class="wp-block-paragraph">This concern was echoed by several other Members, with Lord Vaux of Harrowden succinctly stating,&nbsp;<em>‘We must get this Bill right. If we do not, we risk substantial damage to the economy, businesses, individuals’’ privacy rights – especially children – and even, as far as the surveillance elements go, to our status as a free and open democratic society.’<br></em><a href="https://www.dpocentre.com/dpdi/" target="_blank" rel="noreferrer noopener"><strong>Read the key differences between the UK GDPR and DPDI</strong></a></p>



<h2 class="wp-block-heading"><strong>Canada seeks to update and strengthen its privacy laws</strong></h2>



<p class="wp-block-paragraph">There have been significant developments in Canada’s privacy laws this year. On 24 April, the Canadian House of Commons agreed on the entirety of Bill C-27, the Digital Charter Implementation Act 2022, which seeks to update and strengthen the Personal Information Protection and Electronic Documents Act (PIPEDA), including Canada’s first AI legislation.</p>



<p class="wp-block-paragraph"><strong>In Quebec</strong>, ‘An Act to modernise legislative provisions as regards the protection of personal information’ came into effect in 22 September 2023, with the right to portability under this Act is due to come into force on 22 September 2024.<br><a href="https://www.canlii.org/en/qc/laws/astat/sq-2021-c-25/latest/sq-2021-c-25.pdf" target="_blank" rel="noreferrer noopener"><strong>Read the PDF of Bill 64</strong>&nbsp;</a></p>



<h2 class="wp-block-heading"><strong>The United States sees a wave of new privacy laws</strong></h2>



<p class="wp-block-paragraph">It was a big year for privacy in the US, with 5 new state privacy laws:</p>



<ul class="wp-block-list">
<li>California Privacy Rights Act (CPRA) came into effect on 1 January 2023 and amends the California Consumer Privacy Act (CCPA)</li>



<li>Virginia Consumer Data Protection Act (VCDPA) came into effect on 1 January 2023</li>



<li>The Colorado Privacy Act (CPA) came into effect on 1 July 2023</li>



<li>The Connecticut Data Privacy Act (CTDPA) came into effect on 1 July 2023</li>



<li>The Utah Consumer Privacy Act (UCPA) will come into effect on 31 December 2023</li>
</ul>



<p class="wp-block-paragraph">These laws reflect a shift towards greater consumer control over personal data and increased obligations for organisations in terms of data processing. They also indicate a move towards harmonising state-level laws with global standards, providing new consumer rights aligned with those in the GDPR.</p>



<h2 class="wp-block-heading"><strong>Looking ahead: Data protection in 2024</strong></h2>



<p class="wp-block-paragraph"><a href="https://thedpia.com/" target="_blank" rel="noreferrer noopener"><strong>Subscribe to The DPIA</strong></a>&nbsp;– Keep updated on the latest, most important data protection news with our fortnightly email newsletter.</p>



<p class="wp-block-paragraph"><strong>UK’s DPDI Bill</strong></p>



<p class="wp-block-paragraph">As we move into 2024, all eyes are carefully watching the progress of the proposed Data Protection and Digital Information (DPDI) Bill. The hope of the data protection industry is that the Lords will take into consideration their numerous concerns and apply rigorous scrutiny to the proposed legislation. But only time will tell. We will keep you updated soon as we have further information.</p>



<p class="wp-block-paragraph"><strong>3<sup>rd</sup>&nbsp;party cookies in Chrome to be disabled</strong></p>



<p class="wp-block-paragraph">Google’s plan to phase out 3<sup>rd</sup>&nbsp;party cookies in its Chrome browser begins in quarter 1 of 2024. This is part of a larger initiative called the&nbsp;<strong><a href="https://privacysandbox.com/" target="_blank" rel="noreferrer noopener">Privacy Sandbox</a></strong>&nbsp;project, which aims to reduce cross-site tracking whilst still allowing functionality to keep online services and content freely available.</p>



<p class="wp-block-paragraph">Google will disable 3<sup>rd</sup>&nbsp;party cookies for 1% of users from early January, applying the changes to 100% of users by Q3 2024. The full rollout depends on Google addressing the competition concerns of the UK’s Competition and Markets Authority (CMA). The phasing out of non-essential cookies is in line with the wider global trend towards enhanced data protection and privacy.</p>



<p class="wp-block-paragraph"><a href="https://digital-strategy.ec.europa.eu/en/policies/eprivacy-regulation" target="_blank" rel="noreferrer noopener"><strong>The EU’s</strong>&nbsp;<strong>proposed ePrivacy Regulation</strong></a>&nbsp;establishes clearer rules on cookies, with a more streamlined solution for settings:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><em>‘no consent is needed for non-privacy intrusive cookies that improve internet experience, such as cookies to remember shopping-cart history or to count the number of website visitors.’ (Proposal for an ePrivacy Regulation)</em></p>
</blockquote>



<p class="wp-block-paragraph"><strong>International data transfers</strong></p>



<p class="wp-block-paragraph"><strong>SCCs and IDTA</strong>&nbsp;– From 21 March 2024, UK organisations can no longer use the old EU Standard Contractual Clauses (SCCs) for restricted data transfers. Instead, they must rely on the UK’s International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum (‘UK Addendum’).</p>



<p class="wp-block-paragraph"><strong>EU-UK adequacy</strong>&nbsp;– Later in 2024, the European Commission is due to review the EU-UK adequacy, which will expire on 27 June 2025. The outcome of the UK’s proposed DPDI Bill could significantly affect this decision and create further complications for organisations operating across multiple jurisdictions.</p>



<p class="wp-block-paragraph"><strong>EDPB action: Right of access by controllers</strong></p>



<p class="wp-block-paragraph">The European Data Protection Board (EDPB) will launch a national action in 2024 on ‘The right of access by controllers’. Each year, the EDPB seeks to prioritise certain topics for data protection authorities (DPAs) to work on at a national level. This will be the third co-ordinated enforcement action to date. The results allow for analysis and insight into the topic, which allows for targeted follow-up at both national and EU levels.</p>



<p class="wp-block-paragraph"><strong>The EU’s AI Act</strong></p>



<p class="wp-block-paragraph">With European Parliamentary Elections scheduled for 6-9 June 2024, the EU is likely to adopt the proposed AI Act in early 2024. Otherwise, the elections could delay its passage until 2025. The Act has seen a certain amount of progress in 2023, with the European Parliament adopting amendments to the proposal on 14 June 2023. However, there have been stumbling blocks, especially over the way generative AI platforms like ChatGPT should be regulated. Big Tech companies have been lobbying to weaken the proposed EU legislation and there have also been calls from the French, German, and Italian governments to reduce some of the stringent measures to ensure AI innovation.</p>



<p class="wp-block-paragraph"><strong>The UK’s AI Regulation Bill</strong></p>



<p class="wp-block-paragraph">The AI Regulation Bill is a Private Member’s Bill, originating in the House of Lords during the 2023-24 session. Last updated on 29 November 2023, the Bill includes provisions for the creation of a body called the AI Authority and the appointment of designated AI officers. The government intends to publish a draft AI risk register for consultation, an updated AI regulatory roadmap, and a monitoring and evaluation report after March 2024.</p>



<h2 class="wp-block-heading"><strong>Data Protection support and advice for 2024</strong></h2>



<p class="wp-block-paragraph">Data protection and privacy is a rapidly evolving industry. The pace of change is a challenge for organisations across all sectors, with new laws and new guidance being released regularly. The ever-pressing need for professional advice and guidance from data protection experts looks set to increase as we move into 2024.</p>



<p class="wp-block-paragraph"><strong>The DPO Centre</strong>&nbsp;offers a range of data protection services, including consultancy, outsourced Data Protection Officers (DPOs), GDPR Representatives and AI Explainability (XAI) Services.</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/data-protection-in-2023-a-year-in-review/">Data Protection in 2023: A year in review</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
