1,290 karma · joined October 8, 2016
Especially interested in systems scaling & IAM and also general interest in most of thing on backend side.
You can reach me via <username>@<username>.net
If that's actual law that's a bit surprising. In many EU countries there are journalistic exceptions (which may or may not apply in this specific case depending on local law)
> (you also can't have a street facing surveillance camera like in the US)
And same here. Usually the limit is that if you do it within GDPR household exemption then you cannot have it facing street, but if you do it on GDPR scope then you need to fulfill the GDPR requirements (e.g. posting notice, be ready to answer GDPR requests, perform balancing tests for recording etc.).
This also heavily relies on recent CJEU ruling (WebGroup/Coyote, 16 June 2026, C-188/24) which essentially opened up the E-Commerce Directive's liability shield that platforms have been relying on so far. Essentially it said that that platform's are not necessarily neutral hosting providers when they control the algorithms that determine the dissemination. So I would expect more rulings to come, but it will take time.
https://www.enforcementtracker.com/ETid-3171 Yangoo. UAE.
https://www.enforcementtracker.com/ETid-1912 Criteo. French.
https://www.enforcementtracker.com/ETid-3162 Intesa Sanpaolo. Italian.
https://www.enforcementtracker.com/ETid-2864 Shein. Chinese.
https://www.enforcementtracker.com/ETid-2306 Enel Energia. Italian.
American companies fines tend to be highest since they are biggest and revenue affects the fine amount.
Another issue is that controllers generally do not need to change their behavior before the final lawful decision which can take a lot of time to go through the court system, especially if it needs CJEU referral. And once the decision comes in force they can often make small changes and restart the whole process.
Also another issue is that DPAs do not often initiate the investigations themselves (unless breach is involved), they only happen at the request of data subjects and not that many people bother making complaints or follow them up. Just yesterday I had to follow up with 9 page reply to the controller's response to the DPA inquiry.
Additionally ePD and GDPR enforcement is sometimes split between different agencies. In those cases GDPR agency tends to wait for ePD case to be solved before investigating the GDPR aspects, often because the ePD consent validity will affects e.g. GDPR legal basis analysis.
They at least use a pattern where you need to accept terms of use & privacy policy when you download an app. Same screen has option to accept other agreements like ACR. However by default "select all" option is highlighted so people will often click that.
Slightly earlier on video they state that certain ad related things got turned on automatically during software updates.
All of these would seem to be "your data", but when they are carefully only including certain aspects (like prompts) in their statements it starts to sound they want to hide something.
[EDIT] Smart Media products terms appear to be at https://us.lgappstv.com/main/terms (for comparison here's UK: https://gb.lgappstv.com/main/terms, there are some other EU versions available for e.g. Germany but I imagine UK terms should be quite close and more accessible for most of readers)
That's not quite accurate according to the article. It was actually worse: There were over 100 searches and some of them were done by officer in question, but some were done by other officers. This was due to lieutenant's order in connection with Jones' citizen complaint. So it wasn't just one officer abusing the system.
So in order to store or read data they would need consent. But consent requirements come from GDPR and it's unlikely that this type of consent would be "freely given" given the impact of refusal.
There's good argument that anti cheat itself would need to be consent based. If you don't accept then you simply don't get placed in games with users who have it enabled.
And as this is something that has already happened there isn't much else the person in question can do. Third parties always have option to just disclose information to whoever asks it, at most you can hold them accountable for it later if it was unlawful. And what accountability exactly means depends on what laws exists. If you want some real accountability for the people/companies involved in these kinds of decisions then get Congress to pass such laws (however impossible it might be).
Of course then it's up to judge to determine if the request was valid or not.
> In other words, “generated locally” does not mean that the complete operation is local. Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image. Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly.
> That relationship is important. C2PA calls this a soft binding: a value derived from, or embedded into, the content so that the content can still be matched with its provenance record after the file-level manifest has been removed. For a watermark soft binding, the value is the watermark’s content identifier. Microsoft cryptographically signed this assertion.
> After an AI result is applied to the Paint canvas, the available formats are still restricted to PNG, JPEG, GIF, and Paint’s own .paint format. BMP—the classic Paint format—is conspicuously absent.
Personally it didn't bother me too much.
It doesn't explicitly say it, but there is hardly any other reason why it would add server generated ID (from authenticated session) to the saved file.
At least it didn't (hopefully?) start the driving by reloading the gun like Neuro did https://www.youtube.com/watch?v=LQ0VEDNR_jE
Civil liability is helpful because tax payers do care about $$$ (if judgements/settlements are starting to eat major part of budget the people will start to care on how to lower those costs) and victims are not limited by what prosecutors are ready to do. The QI is especially problematic because it has essentially become "did someone prosecute cops about this before" because that's effectively the only way to establish precedence that allows you to get across the QI-line in future for sufficiently similar conduct. And like you said, prosecutors are often unwilling to prosecute cops.
> Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful conduct, provided that an appropriate balance is struck between the employer’s interests and the employee’s dignity and privacy, and that the control concerns data acquired after the suspicion arose.
> ‘controller’ means the natural or legal person
There have been various cases where individuals have been determined to be separate controllers. For example there have been many cases where doctors/nurses/police looked into the employer's databases without having professional need and were determined to be separate controllers and were fined under GDPR.
* Who actually determines the essential means and purposes for each processing purpose (and is truly doing it). Fashion ID case is quite relevant here.
* If terms which grant Meta these rights and user a lot of obligations would fall under unfair terms or unfair commercial practices directives. If they do then those aspects of the terms are invalid. These could, for example, affect requirement that the user must get consent from data subject for Meta's processing operations.
And I believe in case of European users the contract is between Meta Ireland and user, Meta Ireland is the one who would be the one doing the exporting in that case.
Now if user actually did publish it on Meta's service for broader consumption then they might become controller for that & if initial purpose was that then the initial recording is unlikely to be exempted under household exemption.
> The first layer concerns the primary way in which the controller first engages with the data subject. At this stage, controllers may use a warning sign showing the relevant information. The displayed information may be provided in combination with an icon in order to give, in an easily visible, intelligible and clearly readable manner, a meaningful overview of the intended processing (Article 12 (7) GDPR). The format of the information should be adjusted to the individual location (WP89 par. 22).
> The information should be positioned in such a way that the data subject can easily recognize the circumstances of the surveillance before entering the monitored area (approximately at eye level). It is not necessary to reveal the position of the camera as long as there is no doubt as to which areas are subject to monitoring and the context of surveillance is clarified unambiguously
> The first layer information (warning sign) should generally convey the most important information, e.g. the details of the purposes of processing, the identity of controller and the existence of the rights of the data subject, together with information on the greatest impacts of the processing
While recording by these might not always implicate GDPR directly (as it might be exempted under household exemption or the broader allowances given for journalistic purposes), it does give good idea on how unambiguous it should be.