The EU-US Data Privacy Framework is finally a reality. Today the European Union announced the approval of the much-awaited Adequacy decision (see here), officially recognising the United States as a country that provides sufficient protections for the data of EU citizens which is transferred across the Atlantic. The decision comes following lengthy negotiations and a long period ...
About: Paolo Balboni
Recent Posts by Paolo Balboni
5 years of the GDPR: A call for sustainability

Today we celebrate 5 years of GDPR enforcement, the “birthday” of our revolutionary European legal data protection framework. Each year, I look forward to this anniversary and take time to reflect on the past, present, and future of data protection. While criticizing enforcement of the GDPR seems to be in vogue as of late, I remain ...
Training the Data Protection Authority of Rwanda
Yesterday and today I have had the privilege of training the Data Protection Authority of Rwanda. We had very interesting discussions at the core of matter, e.g., on the the concept of personal data, on anonymisation, pseudonymisation, tokenisation and encryption, the operationalisation of the risk-based approach, etc. The new Rwandan law relating to the protection ...
3rd UM-DPCSR Permanent Stakeholder meeting
This afternoon Kate Francis and I presented Principle 2 of the Maastricht University Data Protection as a Corporate Social Responsibility Framework (UM-DPCSR Framework) to the Members of the Permanent Stakeholder Group, a community of Data Protection, Intergovernmental, Education, and Business Stakeholders who are helping us to gauge the feasibility of the controls we have identified to ...
DPCSR at the 2023 Privacy Symposium in Venice
This morning I moderated the Privacy, ESG and CSR panel at the 2023 Privacy Symposium Conference in Venice. Many thanks to panelists Immaculate Kassait, MBS (Data Protection Commissioner of Kenya), Sophie Nerbonne (CNIL), Guido Scorza (GPDP), Massimo Marelli (International Committee of the Red Cross), Cosimo Monda (ECPC), Sara Agnello (Stellantis), and Emerald De Leeuw-Goggin (Logitech). It was truly remarkable to hear representatives of Supervisory Authorities involved agree that privacy and data ...
2nd UM-DPCSR Permanent Stakeholder Group Meeting
Yesterday we held the second meeting of the Data Protection as a Corporate Social Responsibility (UM-DPCSR) Permanent Stakeholder Group! We discussed Principle 1, comprised of five Rules. We specifically considered the application of the controls. In the coming days, we will share a survey with the Permanent Stakeholders to identify best practices in their relevant ...
1st Data Protection as a Corporate Social Responsibility (DPCSR) Permanent Stakeholder Group Meeting
We are very happy to have kicked off the Data Protection as a Corporate Social Responsibility (DPCSR) Permanent Stakeholder Group today! Over the course of the next six months, together with this group of like-minded persons from Data Protection Supervisory Authorities, Intergovernmental Organizations, Education, and Industry, we will work to concretely improve our digital society ...
Happy Data Protection Day 2023!
Today is Data Protection Day, the day when we celebrate the anniversary of Convention 108 opening for signature. Convention 108 is the first legally binding international law aiming to ensure that the fundamental rights of individuals are respected in the context of personal data processing activities. Each year when January 28th comes around, I ask ...
Are the GEDI Group’s cookie banners compliant with the GDPR?
In recent weeks, cookies have received a great deal of attention in Italy after Italian media conglomerate, GEDI Gruppo Editoriale S.p.A., implemented new cookie banners across a number of its websites (e.g., La Repubblica, La Stampa, Huffpost, Il Secolo XIX). GEDI is not alone, however, as other major Italian newspapers such as Corriere della Sera, ...
Draft adequacy decision for the EU-U.S. Data Privacy Framework
This afternoon, the European Commission announced that it has (finally) finalised its much-awaited draft adequacy decision for the EU-U.S. Data Privacy Framework. According to the Commission, the draft adequacy decision “reflects the assessment by the Commission of the US legal framework and concludes that it provides comparable safeguards to those of the EU”. The decision has been sent to ...
Recent Comments by Paolo Balboni
No comments by Paolo Balboni yet.
CONNECT