EDPO (European Data Protection Office)’s cover photo
EDPO (European Data Protection Office)

EDPO (European Data Protection Office)

Legal Services

Brussels, Brussels Region 80,140 followers

Your Data Protection Representative in the EU, UK and Switzerland

About us

YOUR DATA PROTECTION REPRESENTATIVE IN THE EU/UK/SWITZERLAND > EDPO acts as your Data Protection Representative for companies that fall within the scope of Art 27 of the EU GDPR, Art. 27 of the UK GDPR and Art. 14 of the Swiss Data Protection Law. EDPO is a privately-held Belgian limited liability company with headquarters in Brussels, the European capital, and offices throughout Europe. EDPO also has two sister companies EDPO UK Ltd (located in London) and EDPO Switzerland (located in Geneva). Our fee are all-inclusive and cover the following services:: > The handling of an unlimited number of requests from individuals (data subjects) in the EU/UK/Switzerland, including translation > The handling of an unlimited number of requests from the data protection authorities > Assistance with the handling of an unlimited number of data breach notifications > The right to use EDPO’s contact details and logo on the company’s website and on other company material > The right to use the EDPO compliance certificate (which is based on Blockchain technology) (https://www.edpo.brussels/get-your-edpo-compliance-certificate) > Alerts regarding relevant data protection and GDPR-related news and developments We believe in the GDPR's high standards of data protection. We also believe in the benefits of international trade. Our mission is to enable companies to have access to customers in the EU, the UK and in Switzerland. We help your business grow and protect EU, UK and Swiss customers.

Website
https://edpo.com
Industry
Legal Services
Company size
2-10 employees
Headquarters
Brussels, Brussels Region
Type
Privately Held
Specialties
GDPR and DPR

Locations

Employees at EDPO (European Data Protection Office)

Updates

  • “Hungary’s new government insists that reforms under former Prime Minister Viktor Orbán, allowing facial recognition technology to be used for even minor infractions, are in line with EU AI rules. The former Orbán government adopted the changes last spring in the lead-up to the annual Pride parade in Budapest. Authorities banned the event, reportedly deploying cameras along the route when the march took place anyway and threatening to use facial recognition to identify participants. […] Just last month, the EU’s executive decided to release several billions worth of EU funding to Budapest that had been frozen over rule of law concerns. Should the Commission have concerns about Hungary’s AI surveillance, it would be unlikely to impact on the releasing of further EU funds still tied up, according to Tineke Strik – the Green MEP responsible for the matter in Parliament”. #AI #EU #Hungary #EUCommission #Orbángovernment Subscribe to EDPO's newsletter here: https://lnkd.in/dwK8sde *This article was not written by EDPO. The opinions and views of the author(s) do not necessarily reflect those of EDPO. https://lnkd.in/eF6sbQi4

  • "The Croatian data protection authority (AZOP) imposed a €2.59 million fine on a casino company for collecting fingerprints and photographs in violation of the GDPR. The authority found that the company violated the principle of data minimization by collecting four fingerprints without demonstrating that doing so was necessary. It also found that the company’s consent was invalid because multiple processing purposes were bundled together.   [...] The decision offers the following important takeaways for US-based companies.   First, making biometric processing optional does not eliminate the obligation to limit collection to what is necessary for the stated purpose. A company should be prepared to demonstrate why each data element is needed and why the same purpose cannot be achieved through less extensive collection. U.S. privacy laws impose similar data minimization requirements, and regulators have signaled that they intend to enforce them.   Second, consent is not a workaround for data minimization. Even carefully drafted consent cannot make excessive data collection lawful. Where consent is relied upon, each purpose must be clearly identified and presented in a way that allows individuals to make a specific and meaningful choice." #Privacy #GDPR #CroatianDPA #DataMinimization Subscribe to EDPO's newsletter here: https://lnkd.in/dwK8sde *This article was not written by EDPO. The opinions and views of the author(s) do not necessarily reflect those of EDPO. https://lnkd.in/eSS3aVnC

  • "Asos users across the UK have been sent pop-up messages from its app that appear to have been sent by hackers trying to extort the company. Dozens of people have told the BBC about receiving a strange message from the clothing and beauty store's app, appearing on their phone screens. 'Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,' the message reads. [...] It is not known if ASOS is a customer of Snowflake or what data, if any, is stored with the service. [...] Dan Bird, from cyber security firm Horizon3 says the pop up message the criminals sent implies that their access has gone beyond the Snowflake database. 'Sending a push notification to ASOS's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised.' #Privacy #GDPR #ASOS #DataBreach   Subscribe to EDPO's newsletter here: https://lnkd.in/dwK8sde   *This article was not written by EDPO. The opinions and views of the author(s) do not necessarily reflect those of EDPO. https://lnkd.in/gv8ChYzB

  • "OpenAI will start adding an invisible watermark to text generated by ChatGPT and Codex in the European Union to comply with the EU AI Act, the company said Monday in a blog post. The EU AI Act's transparency rules, which took effect on August 2, require AI companies to mark AI-generated content in a way other systems can identify. OpenAI said the watermark will roll out over the coming weeks to eligible ChatGPT and Codex users on all plans, but only in the EU. Developers using OpenAI's API anywhere in the world can turn it on for select models starting today; it's off by default. OpenAI said it is not making text watermarking a global default at launch. [...] Can the watermark be removed by editing? OpenAI's tests suggest yes. In one test, replacing 10% of words with synonyms dropped detection from about 92% to 66%. The company also said short passages, math answers, and translated text are harder to detect. [...] Anthropic, Google, Meta, Microsoft and OpenAI are among the companies that have committed to following the EU's code of practice on AI-generated content." #Privacy #GDPR #AIAct #Transparency   Subscribe to EDPO's newsletter here: https://lnkd.in/dwK8sde   *This article was not written by EDPO. The opinions and views of the author(s) do not necessarily reflect those of EDPO. https://lnkd.in/ecqxVXm6

  • Outside the EU? GDPR may still apply. The GDPR does not only concern companies established in Europe. If your company is based outside the EU and the GDPR applies to you, you may need to appoint a representative in the EU. The representative acts as your physical point of contact for European authorities, helping ensure your organisation remains reachable when required. At EDPO, we support organisations subject to GDPR obligations by acting as their representative in the EU. Not sure whether this requirement applies to your organisation? Our team can help you understand your obligations.

  • This week, EDPO will be in Seattle for the IAPP Privacy. Security. Risk. + AI Governance Global 2026, taking place on 8–9 October. If you’re attending too, we’d be delighted to connect. Feel free to reach out if you’d like to meet during one of the coffee breaks. Not attending the conference but based in Seattle? We’d also be happy to meet for a coffee nearby. You can contact us at info@edpo.com. #Privacy #GDPR #IAPP #IAPPpsr26 #AIGovernance Subscribe to EDPO’s newsletter here: https://lnkd.in/dwK8sde

    • No alternative text description for this image
  • In case you missed it Here is a brief recap of the news and updates we shared last week. OpenAI continued to face scrutiny over agent-related activity, including a reported leak of 53 ChatGPT user images and unauthorised access to Australian government websites during internal training and evaluation. OpenAI apologised to Australia and said it would establish a taskforce with independent Australian expertise to improve processes, including notification. [1] [2] In the EU, Lighthouse Reports filed a formal complaint against the European Commission, alleging that rules around data centre reporting limit public visibility into the energy and water use of individual data centres. [3] In the US, Meta CEO Mark Zuckerberg and Nvidia CEO Jensen Huang were reported to have helped shape “morally binding” AI accords discussed at a White House lunch with President Donald Trump, Speaker Mike Johnson and tech executives. [4] New Mexico asked a judge to order Meta to pay between $35 billion and $40 billion in penalties after a jury found the company had misled consumers about Facebook data privacy in a case linked to the Cambridge Analytica scandal. [5] References: [1] Reuters: OpenAI works to understand full scope of agent activity as user data leak emerges: https://lnkd.in/dSdEtbyJ [2] POLITICO: ‘Do better for Australia’: OpenAI apologizes for unauthorized access: https://lnkd.in/egjUCqD7 [3] POLITICO: EU accused of hiding environmental impact of data centers: https://lnkd.in/eSvi5Esz [4] POLITICO: Inside Zuckerberg, Huang’s push for White House AI pact: https://lnkd.in/efndmZJ5 [5] Reuters: New Mexico wants Meta to pay up to $40 billion in penalties after data privacy trial: https://lnkd.in/e6MemQ8M #privacy #GDPR #dataprotection #OpenAI #meta #EU Subscribe to EDPO's newsletter here: https://lnkd.in/dwK8sde *These articles were not written by EDPO. The opinions and views of the author(s) do not necessarily represent those of EDPO.

    • No alternative text description for this image
  • "One of the largest Dutch eyewear retail chains said on Friday it had suspended sales of Meta's (META.O), Ray-Ban smart glasses in the Netherlands and Belgium amid growing privacy concerns, in one of the first such moves by a retailer.   'This decision follows the ongoing public and political debate surrounding smart glasses and the questions being raised about the conditions under which this technology can be used,' a spokesperson for the Hans Anders chain said. (...)   A Meta spokesperson said the company is continuing to develop the popular glasses. 'Every pair with a camera has a bright light on the front that blinks when you take a photo or video — it can't be turned off, and the camera is disabled if someone covers or tampers with it,' they said. In the Netherlands, privacy regulator AP last month warned that videos made with smart glasses showing identifiable people cannot generally be shared or published without their permission, which would be difficult to obtain in a public place." #privacy #GDPR #dataprotection #meta #smartglasses   Subscribe to EDPO's newsletter here: https://lnkd.in/dwK8sde   *This article was not written by EDPO. The opinions and views of the author(s) do not necessarily represent those of EDPO. https://lnkd.in/eKh5dmtm

  • DPO, legal advisor, representative: same role? Not quite. These roles may all support organisations with regulatory matters, but they serve very different purposes. A DPO or legal advisor provides independent guidance and advice. A representative has a different role: acting on behalf of the organisation and following its instructions as a point of contact with authorities. Understanding this distinction is essential when choosing the right support for your compliance needs. At EDPO, we specialise exclusively in representative services, helping organisations meet their obligations under European regulations.

  • “The state of New Mexico asked a judge on Thursday to order Meta Platforms to pay between $35 billion and $40 billion in penalties after a jury found the company had misled consumers about the privacy of their data on Facebook in a case that came out of the Cambridge Analytica scandal. Attorneys for New Mexico made the request at a hearing in a lawsuit brought following revelations that the British political consulting firm, which worked on Donald Trump's 2016 presidential campaign, harvested personal data from as many as 87 million Facebook users through a third-party app without their consent. The jury returned its verdict on September 25. Judge Francis Mathew, who oversaw the trial in Santa Fe, will decide how much Meta must pay in financial penalties. Attorneys for Meta and New Mexico clashed at the hearing over how much was appropriate to order, with Meta arguing that the penalties ⁠the state was seeking don't match the conduct the state focused its case on at trial.” #Privacy #GDPR #Meta #NewMexico Subscribe to EDPO's newsletter here: https://lnkd.in/dwK8sde *This article was not written by EDPO. The opinions and views of the author(s) do not necessarily reflect those of EDPO. https://lnkd.in/e6MemQ8M

Similar pages

Browse jobs