small-company

Less Known Cambridge Analytica Partner Receives a GDPR Hit

After GDPR coming into force, it was assumed the big players – multinational companies were the first to receive sanctions. However, first action (filed in July and disclosed on September), the Enforcement Notice, was towards AggregateIQ Data Services Ltd (AIQ) . Canadian political consultancy and data analytics company with 20 employees. It helped develop the algorithm used by Cambridge Analytica to target Facebook users in the 2016 US presidential election.

AIQ investigation, run by ICO, started before the GDPR’s effective date. The question was whether the company violated the privacy laws of Canada and British Columbia. At the time, AIQ refused to answer the ICO’s inquiries, claiming the UK agency had no jurisdictional hook to use against the Canadian company. However, the GDPR implicates data controllers and data processors anywhere in the world. Meaning, if a company collects or processes data of people in the European Economic Area, they have to comply with GDPR.  Therefore, the ICO found an angle to pursue action against AIQ.

LEARNING TIP:  Even if your company is based outside EU, GDPR rules still may apply. Meaning that, businesses that are dealing with EU market and processing EU citizens’ personal data (collects, stores or uses),  must comply with GDPR.

Read more…

Subscribe to our Newsletter

Your e-mail address is only used to send you our newsletter and information about the activities of GDPR Register. You can always use the unsubscribe link included in the mail.

Share on facebook
Share on google
Share on twitter
Share on linkedin
Share on pinterest
Share on print
Share on email

Latest Blog Posts

dpa gdpr

Data Protection Authorities (DPA)

Data Protection Authorities (DPA) Data Protection Authorities (DPA) are independent public authorities that supervise, through investigative and corrective powers, the application of the GDPR. They

Read More »

Zpracovává vaše společnost osobní údaje?


Zpracovávat vaše společnost osobní údaje fyzických osob, jako jsou:

  • Údaje zaměstnanců, zákazníků, uchazečů o zaměstnání nebo pacientů včetně:
    • Jméno nebo osobní identifikační číslo
    • Kontaktní údaje (e-mailová adresa, telefonní číslo, adresa)
    • Bankovní údaje, plat, údaje o pasu nebo jiné osobní údaje

 

Ar Jūsų įmonė renka ir tvarko fizinių asmenų asmens duomenis? 


Asmens duomenys gali būti:

  • Kliento, darbuotojo. paciento, kandidato į darbo vietą ir kt. 
    • Vardas ar asmens  numeris 
    • Kontaktinė informacija (el.pašto adresas, telefono numeris, adresas ir kt)
    • Banko sąskaitos  duomenys, atlyginimo dydis, paso duomenys ar bet kokia kita asmeninė informacija. 

Onko yrityksessäsi enemmän, kuin 250 työntekijää?


Kas teie ettevõte kogub ja töötleb isikuandmeid?


Kas teie ettevõte kogub ja töötleb füüsiliste isikutega seotud andmeid nagu näiteks:

Töötajate, klientide, tööle kandideerijate, patsientide:

  • Nimi, isikukood
  • E-posti aadress, telefoninumber, kodune aadress
  • Pangakontonumber, palgasumma, krediitkaardiandmed või mõnda muut tüüpi isiklikud andmed

Does your company collect any personal data?


Does your company collect and process any personal data of natural persons such as:

  • Employees, Customers, Job Applicants or Patients including:
    • Name or personal ID number
    • Contact details (Email address, Phone number, Address)
    • Bank details, Salary amounts, Passport details or any other personal data