Skip to content
ConformallyConformally
  • Business Solutions
    • Free Privacy Policy
    • Free Privacy Resources
    • Full Compliance Solution
  • For Privacy Professionals
    • Privacy Compliance Software
    • Privacy Resource Hub
    • Fine Tracker
  • Pricing
  • Resources
    • GDPR Fine Tracker
    • Laws and Regulations
    • Official Guidelines
    • Decisions and Case Law
    • Templates and Examples
    • Privacy and AI News
    • Software Tools
    • AI Assistant
  • Login
  • Request Demo
Filtered (197)
Filters
  • Reset all ×
  • academic paper ×
  • adequacy decision ×
  • opinion ×
  • recommendations ×
  • template ×
Search
×
Type
Categories
Show (197)
Cancel
  • Reset all ×
  • academic paper ×
  • adequacy decision ×
  • opinion ×
  • recommendations ×
  • template ×
UK ICO Controller ROPA Template

Records of processing Activities (ROPA)

Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

AI

Standard contractual clauses for EU-EEA by EU

Standard Contractual Clauses (SCC)

Standard contractual clauses for international transfers by EU

Data Transfers, Standard Contractual Clauses (SCC)

Decision of 19 October 2010 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data in Andorra

Adequacy Decisions

Decision of 30 June 2003 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data in Argentina

Adequacy Decisions

Decision of 20 December 2001 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data provided by the Canadian Personal Information Protection and Electronic Documents Act

Adequacy Decisions

Decision of 5 March 2010 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection provided by the Faeroese Act on processing of personal data

Adequacy Decisions

Decision of 21 November 2003 on the adequate protection of personal data in Guernsey

Adequacy Decisions

Decision of 31 January 2011 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data by the State of Israel with regard to automated processing of personal data

Adequacy Decisions

Decision of 28 April 2004 on the adequate protection of personal data in the Isle of Man

Adequacy Decisions

Decision (EU) 2019/419 of 23 January 2019 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate protection of personal data by Japan under the Act on the Protection of Personal Information

Adequacy Decisions

Decision of 8 May 2008 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data in Jersey

Adequacy Decisions

Decision of 19 December 2012 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data by New Zealand

Adequacy Decisions

Decision (EU) 2022/254 of 17 December 2021 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate protection of personal data by the Republic of Korea under the Personal Information Protection Act

Adequacy Decisions

Decision of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data provided in Switzerland

Adequacy Decisions

Decision (EU) 2021/1772 of 28 June 2021 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate protection of personal data by the United Kingdom (notified under document C(2021)4800)

Adequacy Decisions

Decision (EU) 2021/1773 of 28 June 2021 pursuant to Directive (EU) 2016/680 of the European Parliament and of the Council on the adequate protection of personal data by the United Kingdom

Adequacy Decisions

Decision EU 2023/1795 of 10 July 2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework

Adequacy Decisions

Decision pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data by the Eastern Republic of Uruguay with regard to automated processing of personal data

Adequacy Decisions

Decision pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data by the Eastern Republic of Uruguay with regard to automated processing of personal data

Adequacy Decisions

Decision pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data by the Eastern Republic of Uruguay with regard to automated processing of personal data

Adequacy Decisions

First Draft General-Purpose AI Code of Practice by EU Commission

AI

Mobile Applications recommendations for better privacy protection by CNIL (french)

Product Privacy Design

Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR by EDPB

Lawfulness of Processing, Legitimate Interest

Recommendations for the use of AI coding assistants by ANSSI and BSI

AI, Specific processing situations

Recommendation on mobile applications or apps by the French DPA

Lawfulness of Processing, Specific processing situations

Privacy Impact Assessment (PIA) Templates by CNIL

Data Protection Impact Assessment (DPIA)

Statement 2/2024 on the financial data access and payments package by EDPB

Finance and Fintech

Opinion 04/2024 on the notion of main establishment of a controller in the Union under Article 4(16)(a) GDPR |EPDB

Definitions, Main Establishment

Opinion 36/2023 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Booking.com Group |EPDB

Data Transfers

Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725) |EPDB

Controllers and Processors, Data Protection Impact Assessment (DPIA)

Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR) |EPDB

Data Transfers

Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data |Version 2.0 |EPDB

Data Transfers

Recommendations 02/2020 on the European Essential Guarantees for surveillance measures |EPDB

Specific processing situations, Surveillance

Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive |EPDB

Adequacy Decisions, Data Transfers

Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions |EPDB

Consent, Lawfulness of Processing

Opinion 31/2023 on the draft decision of the French Supervisory Authority regarding the Controller Binding Corporate Rules of the Thalès Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 32/2023 on the draft decision of the French Supervisory Authority regarding the Processor Binding Corporate Rules of the Thalès Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 33/2023 on the draft decision of the Hesse Supervisory Authority (Germany) regarding the Controller Binding Corporate Rules of the Cerner Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 34/2023 on the draft decision of the Hesse Supervisory Authority (Germany) regarding the Processor Binding Corporate Rules of the Cerner Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 35/2023 on the draft decision of the Danish Supervisory Authority regarding the Controller Binding Corporate Rules of the Carlsberg Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 37/2023 on the draft decision of the competent supervisory authority of Luxemburg regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Certification

Opinion 38/2023 on the draft decision of the competent supervisory authority of Slovenian regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR). |EPDB

Certification

Opinion 01/2024 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Booking.com Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 2/2024 on the draft decision of the Spanish Supervisory Authority regarding the Controller Binding Corporate Rules of the TELEFÓNICA Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 3/2024 on the draft decision of the Irish Supervisory Authority regarding the Processor Binding Corporate Rules of the Accenture Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 23/2023 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules for customer data of the UPS Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 24/2023 on the draft decision of the French Supervisory Authority regarding the Controller Binding Corporate Rules of the Nestlé Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 25/2023 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the SHV Holding N.V. Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 26/2023 on the draft decision of the Romanian Supervisory Authority regarding the Processor Binding Corporate Rules of the OSF Global Services Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 27/2023 on the draft decision of the French Supervisory Authority regarding the Processor Binding Corporate Rules of the Tessi Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 28/2023 on the draft decision of the French Supervisory Authority regarding the Controller Binding Corporate Rules of the Servier Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 29/2023 on the draft decision of the French Supervisory Authority regarding the Controller Binding Corporate Rules of the Sodexo Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 30/2023 on the draft decision of the French Supervisory Authority regarding the Processor Binding Corporate Rules of the Sodexo Group |EPDB

Binding Corporate Rules, Data Transfers

International Data Transfer Agreements – Transitional Provisions

Data Transfers

Transfer Risk Assessment Tool by the UK ICO

Data Transfers

Transfer Impact Assessment (TIA) Template by HSE

Data Transfers

[UK] International Data Transfer Addendum to the EU Commission Standard Contractual Clauses

Data Transfers

[UK] Standard Data Protection Clauses to be issued by the Commissioner under S119A(1) Data Protection Act 2018

Data Transfers

[Draft] Transfer Impact Assessment by the CNIL

Data Transfers

Information Commissioner’s Further Response to the Data Protection and Digital Information Bill (DPDI Bill)

Principles, Sensitive Data

Opinion on processing of CCTV data in regard to employee performance analytics by the Bulgarian DPA

CCTV, Employment, Specific processing situations

DPIA for AI template

Controllers and Processors, Data Protection Impact Assessment (DPIA)

AI Privacy Policy template

AI, Specific processing situations

AI and Data Protection Risk Toolkit by UK ICO

AI, Controllers and Processors, Data Protection Impact Assessment (DPIA), Specific processing situations

Description of the dataset template by CNIL

AI, Specific processing situations

Opinion 44/2023 on the Proposal for Artificial Intelligence Act in the light of legislative developments

AI, Specific processing situations

Data Breach Process Guidance by HSE

Controllers and Processors, Data Breaches

Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679

Recommendation 5: Promote parental controls that respect the child’s privacy and best interests by CNIL

Children as data subjects, Data Subjects Rights

Recommendation 4: Seek parental consent for children under 15 by CNIL

Children as data subjects, Consent, Data Subjects Rights, Lawfulness of Processing

Recommendation 3: Support parents with digital education by CNIL

Children as data subjects, Data Subjects Rights

Recommendation 2: Encourage children to exercise their rights by CNIL

Children as data subjects, Data Subjects Rights

Recommendation 1: Regulate the capacity of children to act online by CNIL

Children as data subjects, Data Subjects Rights

Recommendation 7: Check the age of the child and parental consent while respecting the child’s privacy by CNIL

Children as data subjects, Data Subjects Rights

Recommendation 6: Strengthen the information and rights of children by design by CNIL

Children as data subjects, Data Subjects Rights

Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework by EDPB

AI, Specific processing situations

Data protection impact assessment for AI Solutions by Danish DPA

AI, Controllers and Processors, Data Protection Impact Assessment (DPIA), Specific processing situations

EditorsTrends in Data Protection and Encryption Technologies by SpringerProfessional

Definitions, New technology, Processing of personal data

Discussion Paper: Large Language Models and Personal Data by The Hamburg Commissioner for Data protection and freedom of information

AI, Specific processing situations

Exploring the ethical, technical and legal issues of voice assistants by CNIL

Call recordings

Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR by EDPB

Facial Recognition, Specific processing situations

EU-US Data Privacy Framework Template Complaint Form for Submitting Commercial Related Complaints to EU DPAs by EDPB

Adequacy Decisions, Data Transfers

Opinion 18/2021 on the draft Standard Contractual Clauses submitted by the LT SA (Article 28(8) GDPR) |EDPB

Controllers and Processors, Data Transfers, Standard Contractual Clauses (SCC)

Opinion 26/2021 on the draft decision of the Supervisory Authority of North Rhine-Westphalia (Germany) regarding the Controller Binding Corporate Rules of the Internet Initiative Japan Group |EDPB

Binding Corporate Rules, Data Transfers

Opinion 27/2021 on the draft decision of the Supervisory Authority of North Rhine-Westphalia (Germany) regarding the Processor Binding Corporate Rules of the Internet Initiative Japan Group |EDPB

Binding Corporate Rules, Data Transfers

Opinion 28/2021 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules of Oregon Tool, Inc (formerly “Blount”) |EDPB

Binding Corporate Rules, Data Transfers

Opinion 29/2021 on the draft decision of the Belgian Supervisory Authority regarding the Processor Binding Corporate Rules of Oregon Tool, Inc (Formerly “Blount”) |EDPB

Binding Corporate Rules, Data Transfers

Opinion 30/2021 on the draft decision of the Spanish Supervisory Authority regarding the Controller Binding Corporate Rules of the COLT Group |EDPB

Binding Corporate Rules, Data Transfers

Opinion 31/2021 on the draft decision of the Spanish Supervisory Authority regarding the Processor Binding Corporate Rules of the COLT Group |EDPB

Binding Corporate Rules, Data Transfers

Opinion 21/2021 on the draft decision of the French Supervisory Authority regarding the Controller Binding Corporate Rules of the CGI Group |EDPB

Binding Corporate Rules, Data Transfers

Opinion 22/2021 on the draft decision of the French Supervisory Authority regarding the Processor Binding Corporate Rules of the CGI Group |EDPB

Binding Corporate Rules, Data Transfers

Opinion 14/2021 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data in the United Kingdom |EPDB

Adequacy Decisions, Data Transfers

Opinion 15/2021 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data in the United Kingdom |EDPB

Adequacy Decisions, Data Transfers

Opinion 19/2021 on the draft decision of the competent supervisory authority of Hungary regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EDPB

Accreditation

Opinion 32/2021 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data in the Republic of Korea |EDPB

Adequacy Decisions, Data Transfers

EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

AI, Specific processing situations

Opinion 20/2021 on Tobacco Traceability System |EDPB

Controllers and Processors, Data Sharing

Personal data breach report form

Controllers and Processors, Data Breaches

Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms by EDPB

Consent, Lawfulness of Processing

Opinion 23/2021 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR |EDPB

Code of Conduct, Controllers and Processors

Opinion 24/2021 on the draft decision of the competent supervisory authority of Slovakia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR |EDPB

Code of Conduct, Controllers and Processors

Opinion 25/2021 on the draft decision of the competent supervisory authority of Lithuania regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EDPB

Accreditation

Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe |EDPB

Code of Conduct, Controllers and Processors

Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE) |EDPB

Code of Conduct, Controllers and Processors

Report and Recommendations of the New York State Bar Association Task Force on Artificial Intelligence

AI, Specific processing situations

Opinion 03/2022 on the draft decision of the French Supervisory Authority regarding the Processor Binding Corporate Rules of the WEBHELP Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 30/2021 on the draft decision of the Spanish Supervisory Authority regarding the Controller Binding Corporate Rules of the COLT Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 31/2021 on the draft decision of the Spanish Supervisory Authority regarding the Processor Binding Corporate Rules of the COLT Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 33/2021 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules of Carrier |EPDB

Binding Corporate Rules, Data Transfers

Opinion 34/2021 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules of Otis |EPDB

Binding Corporate Rules, Data Transfers

Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject |EPDB

Data Controller, Data Subjects Rights, Definitions

Opinion 35/2021 on the draft decision of the competent supervisory authority of Belgium regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

Opinion 36/2021 on the draft decision of the competent supervisory authority of Norway regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

Opinion 37/2021 on the draft decision of the competent supervisory authority of Malta regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR |EPDB

Accreditation

Opinion 38/2021 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

Opinion 08/2022 on the draft decision of the Danish Supervisory Authority regarding the Controller Binding Corporate Rules of Bioclinica Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 06/2022 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of Groupon International Limited |EPDB

Binding Corporate Rules, Data Transfers

Opinion 05/2022 on the draft decision of the Danish Supervisory Authority regarding the Controller Binding Corporate Rules of the Lundbeck Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 07/2022 on the draft decision of the Hungarian Supervisory Authority regarding the Controller Binding Corporate Rules of MOL Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 04/2022 on the draft decision of the Danish Supervisory Authority regarding the Controller Binding Corporate Rules of Norican Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 32/2021 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data in the Republic of Korea |EPDB

Adequacy Decisions, Data Transfers

EDPB-EDPS Joint Opinion 1/2022 on the Proposal for a Regulation of the European Parliament and of the Council amending Regulation (EU) 2021/953 on a framework for the issuance, verification and acceptance of interoperable COVID-19 vaccination, test and recovery certificates (EU Digital COVID Certificate) to facilitate free movement during the COVID-19 pandemic |EPDB

Health Data, Principles, Sensitive Data

EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)

Data Transfers

Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria |EPDB

Certification

Opinion 12/2022 on the draft decision of the competent supervisory authority of France regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

Opinion 13/2022 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

Opinion 14/2022 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR |EPDB

Code of Conduct, Controllers and Processors

Opinion 15/2022 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR |EPDB

Code of Conduct, Controllers and Processors

Opinion 16/2022 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR |EPDB

Code of Conduct, Controllers and Processors

Opinion 17/2022 on the draft decision of the Spanish Supervisory Authority regarding the Controller Binding Corporate Rules of the ANTOLIN Group |EPDB

Binding Corporate Rules, Data Transfers

EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

Health Data, Principles, Sensitive Data

EDPB-EDPS Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse

Children as data subjects, Data Subjects Rights

Opinion 25/2022 regarding the European Privacy Seal (EuroPriSe ) certification criteria for the certification of processing operations by processors |EPDB

Certification

Opinion 18/2022 on the draft decision of the Baden-Württemberg (Germany) Supervisory Authority regarding the Controller Binding Corporate Rules of the Daimler Truck Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 19/2022 on the draft decision of the Baden-Württemberg (Germany) Supervisory Authority regarding the Controller Binding Corporate Rules of the MercedesBenz Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 20/2022 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Ellucian Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 21/2022 on the draft decision of the Irish Supervisory Authority regarding the Processor Binding Corporate Rules of the Ellucian Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 22/2022 on the draft decision of the Liechtenstein Supervisory Authority regarding the Controller Binding Corporate Rules of Hilti Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 23/2022 on the draft decision of the Swedish Supervisory Authority regarding the Controller Binding Corporate Rules of the Samres Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 24/2022 on the draft decision of the Swedish Supervisory Authority regarding the Processor Binding Corporate Rules of the Samres Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 26/2022 on the draft decision of the Data Protection Authority of Bavaria for the Private Sector regarding the Controller Binding Corporate Rules of the Munich Re Reinsurance Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 09/2022 on the draft decision of the Danish Supervisory Authority regarding the Processor Binding Corporate Rules of Bioclinica Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 10/2022 on the draft decision of the Hesse Supervisory Authority (Germany) regarding the Controller Binding Corporate Rules of Fresenius Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 02/2022 on the draft decision of the French Supervisory Authority regarding the Controller Binding Corporate Rules of the WEBHELP Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 31/2022 on the draft decision of the Slovak Supervisory Authority regarding the Processor Binding Corporate Rules of Piano Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 32/2022 on the draft decision of the Danish Supervisory Authority regarding the Controller Binding Corporate Rules of the Ramboll Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 11/2023 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR |EPDB

Accreditation

Opinion 12/2023 on the draft decision of the competent supervisory authority of Cyprus regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

Opinion 13/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

Opinion 14/2023 on the draft decision of the Danish Supervisory Authority regarding the Controller Binding Corporate Rules of the Vestas Wind Systems Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria |EPDB

Certification

Opinion 18/2023 on the draft decision of the Belgian Supervisory Authority regarding the Processor Binding Corporate Rules of the Collibra Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 19/2023 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the American Express Global Business Travel Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 20/2023 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Comcast Corporation Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 21/2023 on the draft decision of the Belgian Supervisory Authority regarding the Processor Binding Corporate Rules of the UPS Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 22/2023 on the draft decision of the Belgian Supervisory Authority regarding the Controller Binding Corporate Rules for employee data of the UPS Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 7/2023 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of Autodesk Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 8/2023 on the draft decision of the Irish Supervisory Authority regarding the Processor Binding Corporate Rules of Autodesk Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 5/2023 on the European Commission Draft Implementing Decision on the adequate protection of personal data under the EU-US Data Privacy Framework |EPDB

Adequacy Decisions, Data Transfers

Opinion 9/2023 on the draft decision of the Italian Supervisory Authority regarding the Controller Binding Corporate Rules of Vertiv |EPDB

Binding Corporate Rules, Data Transfers

Opinion 10/2023 on the draft decision of the Spanish Supervisory Authority regarding the Controller Binding Corporate Rules of the PROSEGUR Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 16/2023 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Informatica Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 17/2023 on the draft decision of the Irish Supervisory Authority regarding the Processor Binding Corporate Rules of the Informatica Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 11/2022 on the draft decision of the competent supervisory authority of Poland regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR |EPDB

Code of Conduct, Controllers and Processors

Opinion 02/2023 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR |EPDB

Code of Conduct, Controllers and Processors

Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR |EPDB

Code of Conduct, Controllers and Processors

Opinion 4/2023 on the draft decision of the competent supervisory authority of Malta regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) |EPDB

Accreditation

EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro

Accreditation

EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679

Accreditation

Opinion 6/2023 on the draft decision of the Danish Supervisory Authority regarding the Controller Binding Corporate Rules of Royal Greenland Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 27/2022 on the draft decision of the French Supervisory Authority regarding the Processor Binding Corporate Rules of LEYTON Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 28/2022 on the Europrivacy criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR) |EPDB

Certification

Opinion 29/2022 on the draft decision of the Danish Supervisory Authority regarding the Controller Binding Corporate Rules of the DSV Group |EPDB

Binding Corporate Rules, Data Transfers

Opinion 30/2022 on the draft decision of the Slovak Supervisory Authority regarding the Controller Binding Corporate Rules of Piano Group |EPDB

Binding Corporate Rules, Data Transfers

Zapier’s Transfer Impact Assessment

Data Transfers

Opinion on legitimate interests of the data controller (Opinion 06/2014)

Legitimate Interest

Opinion 05/2014 on Anonymisation Techniques | WP216

Anonymisation

Joint Guide to ASEAN MCC and EU SCC

Data Transfers, Standard Contractual Clauses (SCC)

Data Protection Impact Assessments (DPIA) Template by UK ICO

Data Protection Impact Assessment (DPIA)

Data Protection Impact Assessment (DPIAs) by APDCAT

Data Protection Impact Assessment (DPIA)

COMMISSION IMPLEMENTING DECISION of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework

Adequacy Decisions, Data Transfers

Records of processing activities template by the CNIL

Records of processing Activities (ROPA)

Why a right to explanation of automated decision-making does not exist in the General Data Protection Regulation

Data Subjects Rights

Recommendations for companies planning to use Cloud computing services by CNIL

Cloud Services

How Google Uses Information on websites [link]

AT&T Privacy Notice

Data Subjects Rights

AI Development Recommendations to Ensure GDPR Compliance by CNIL

AI, Specific processing situations

Statement 2/2024 on the financial data access and payments package bg EDPB

Finance and Fintech

Template Complaint Form to the U.S. Office of the Director of National Intelligence’s Civil Liberties Protection Officer (CLPO) by EDPB

Adequacy Decisions, Data Transfers

Technical and organisational measures signed by Superhosting.bg

Controllers and Processors, Technical and Organisational Measures (TOMs)

Technical and Organizational Measures by Adobe Cloud Services

Controllers and Processors, Technical and Organisational Measures (TOMs)

Privacy Program 247.ai

[UK] International Data Transfer Addendum to the EU Commission Standard Contractual Clauses

Data Transfers

[UK] International Data Transfer Agreements – Transitional Provisions

Data Transfers

Resources

  • Privacy Compliance
  • Book a Demo

Resources

  • Fine Tracker
  • Privacy Policy Generator

Terms and Conditions Privacy Policy Your Privacy Choices 
© 2024 Conformally | Sofia, Bulgaria

  • Business Solutions
    • Free Privacy Policy
    • Free Privacy Resources
    • Full Compliance Solution
  • For Privacy Professionals
    • Privacy Compliance Software
    • Privacy Resource Hub
    • Fine Tracker
  • Pricing
  • Resources
    • GDPR Fine Tracker
    • Laws and Regulations
    • Official Guidelines
    • Decisions and Case Law
    • Templates and Examples
    • Privacy and AI News
    • Software Tools
    • AI Assistant
  • Login
  • Request Demo
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Cookie SettingsReject AllAccept
Manage consent

Основна Информация

Този сайт използва "бисквитки" и други технологии за проследяване за подпомагане на навигацията и възможността ви да предоставяте обратна информация, да анализирате използването на нашите продукти и услуги.
Бисквитките („Cookies“’) представляват малко количество информация, която уеб сървърът изпраща на уеб браузъра, позволявайки на сървъра да събира обратна информация от браузъра. Потребителят може да избере да изтрие бисквитките чрез опциите на всеки браузър. Използваните от Администратора бисквитки са такива свързани с функционалността на сайта, ефективността на сайта и такива позволяващи да се запомнят предпочитанията на потребителите. Повече информация за „cookies” можете да намерите на: http://www.allaboutcookies.org/faqs/cookies.html
Necessary
Always Enabled
За да може да функционира нашият сайт използваме необходими бисквитки. Те съдържат информация за количката като цяло и помагат на сайта да знае кога данните за количката се променят. \"Бисквитката\" _session_ съдържа уникален код за всеки клиент, така че да знае къде да намери данните за количката в базата данни. В тези бисквитки не се съхранява лична информация.
Non-necessary
Използваме тези бисквитки с цел реклама и подобряване на клиентското преживяване на www.legal-tech.bg Чрез тези бисквитки събираме данни за Вашето поведение на сайта. Данни се изтриват 12 месеца след тяхното събиране; Данните се предоставят на 3-ти лица като Гугъл, Фейсбук и други подобни доставчици на рекламни услуги.
SAVE & ACCEPT