The EDPB issued its recommendations on how to deal with transfers of personal data outside the EEA after the Schrems II case, which have a major impact on any business.
The Fintech revolution relies on data flows enhanced by the PSD2, which requires certainty now aimed by the European Data Protection Board guidelines on the interplay between the PSD2 and the GDPR, which leave gray areas though.
After the position taken by the ECJ in the Planet49 case, the EDPB in its guidelines, also the German federal court held that privacy consent is necessary to the usage of cookies.
On the birthday of the GDPR, we need to defend privacy rights against the strategy of companies, and authorities that want to challenge or waive them due to the Covid-19 outbreak, assuming to better protect the public interests.
The Garante took a more open view on compliance of coronavirus checks with privacy laws in Italy, which is more flexible but still provides stringent obligations.