Anyone who regularly works with Ailance RoPA is familiar with this: you are constantly switching back and forth between processing activities, parties involved and data protection impact assessments (DPIAs). The focus and
Third-party risk management (TPRM) is a central element of modern corporate management. It creates the basis for complying with legal requirements, reducing liability risks and gaining the trust of third parties.
The data protection assessment of health data in the employment relationship is one of the most sensitive aspects of compliance practice. A current occasion for in-depth discussion is the publication of the
The popular video editing app CapCut from ByteDance, which also owns TikTok, updated its terms of use on June 12, 2025. These now provide for a comprehensive
On June 16, 2025, the Conference of Independent Federal and State Data Protection Supervisory Authorities (DSK) adopted the Model Guidelines for the Procedure on Fines (MRiDaVG).
In June 2025, the French data protection supervisory authority CNIL published guidance on the application of the "legitimate interest" (Art. 6 para. 1 lit. f GDPR) as a
While compliance issues have often been dealt with in silos in the past, the reality is that data protection, information security, business continuity and legal obligations are closely linked.
The French competition authority (Autorité de la concurrence) sentenced Apple to a fine of 150 million euros on March 31, 2025. The reason is the abuse
In June, the data protection authorities in Spain and Italy were particularly active and issued large fines. The highest fine was imposed on an energy company - for
The General Data Protection Regulation (GDPR) has been in force since 25.05.2018. For the first time, it regulates how companies are allowed to handle personal data in a uniform manner across Europe. How consumers and companies can benefit after six