Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

EDPB Issues Opinion Clarifying Rules for 'Consent or Pay' Models

The European Data Protection Board has adopted a formal opinion on the validity of 'consent or pay' business models used by large online platforms. The opinion states that in most cases, these models will not constitute valid consent under the GDPR. The EDPB emphasizes that offering only a paid alternative to services that process personal data for behavioral advertising is generally not a compliant approach. The guidance stresses the need for a 'free alternative without behavioral advertising' so users are not forced to pay to protect their fundamental right to data protection.

Today's question

Under Article 34 GDPR, notification to data subjects of a breach is required when:

  1. Only when financial data is involved, following established incident response procedures, subject to documented procedural requirements
  2. The supervisory authority requests it in all cases, under the data breach management framework
  3. Every breach must be communicated to data subjects, as required under the breach notification provisions
  4. The breach is likely to result in a high risk to the rights and freedoms of natural persons

Answer this question on the site

Worth knowing

  1. OpenAI Announces Partnership to Train AI on Reddit Content

    OpenAI has entered into a partnership with Reddit, granting it access to the platform's real time content stream through the Reddit Data API. This data will be used to enhance ChatGPT and develop new products by grounding them in current discussions. The agreement highlights the growing debate over the use of publicly available and user generated data for commercial AI model training.

  2. Maryland Enacts Strong Comprehensive Consumer Privacy Law

    The Governor of Maryland has signed the Maryland Online Data Privacy Act (MODPA), establishing it as one of the strongest state level privacy laws in the United States. The law provides consumers with rights to access, delete, and opt out of data sales and targeted advertising, and notably includes broad definitions of sensitive data and lower applicability thresholds. MODPA will require many businesses to update their US privacy compliance programs before it takes effect.

  3. Norwegian DPA Fines Public Agency €1.7M for Security Failures

    Norway's Data Protection Authority, Datatilsynet, has imposed a significant fine of approximately €1.7 million on the Norwegian Labour and Welfare Administration (NAV). The fine was levied due to inadequate technical and organizational security measures, which failed to properly restrict employee access to citizen data, constituting a breach of GDPR's integrity and confidentiality principle.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.