Get called
Demonstration
To process your request, we need to process your personal data. Find out more about the processing of your personal data here.
Data leaks, record fines, and GDPR tips GDPR everything you need to know this month!
As the year draws to a close, compliance takes no vacation. December saw a historic fine for LinkedIn, a huge data leak at Free, and a court ruling that redefines the rules of the game in terms of competition and GDPR.
But that's not all: we also share practical advice on how to manage a data leak, a reminder of theHR Data retention periods to be aware of, and an overview of CNIL (National Commission for Information Technology and Civil Liberties) checks. And to end the year on a high note: a webinar not to be missed, an exclusive referral offer, and a healthy dose of useful insights.
On the program:
1. GDPR news GDPR the month: New case law, non-compliance with GDPR unfair competition
2. Penalty of the month: €310 million for LinkedIn for non-compliant advertising practices
3. The data leak that everyone is talking about: Data from 19 million Free subscribers on the dark web
4. The GDPR tipfor effectively managing a data breach
5. The top 20 most commonlyused passwordsin France: are you on the list?
6. The CNIL (National Commission for Information Technology and Civil Liberties) monitoring campaign: mobile applications in the spotlight
7. The 4HR Data retention periodsHR remember (and apply)
8. You are invitedto our next webinar on Artificial Intelligence
9. Have you seen our FAQ?
10–15% (cumulative) off your subscription thanks to referrals
October 4, 2024 marks a key milestone: the Court of Justice of the European Union (CJEU) paves the way for unfair competition claims based on non-compliance with GDPR.
Why is this a turning point?In France, this possibility already existed, but it has now been validated at the European level.
What difference does this make?From now on, your competitors can take legal action if you do not comply with the GDPR this gives you an unfair advantage.
Key takeaway: Failure to complywith GDPR unfair competition.
Historic ruling: On October 24, 2024, LinkedIn was fined€310 millionby the Irish Data Protection Commission (DPC) for:
A broader trend: This decision is part of a series of sanctions against digital giants for similar violations of GDPR.
In October 2024, a cyberattack compromised the personal data, including IBANs, of nearly 19 million clients . This information was put up for sale on the dark web.
Timeline:
Consequences: Thiscase highlights security flaws even among major operators. Subscribers are urged to remain vigilant, particularly with regard to phishing and fraud.
Recommended measures for subscribers
✔ Monitoring bank accounts:Regularly check statements for any suspicious activity.
✔ Be cautious with communications:Be wary of unexpected emails or text messages asking for personal or financial information.
✔ Change your login details:Change the passwords for accounts linked to Free and avoid using the same password for multiple services.
| Imagine: you discover a data leak within your organization. And then panic sets in. Here are three steps to respond effectively and limit the consequences: |
As soon as a data breach is suspected or confirmed, immediately notify the Dipeeo team atdpo@dipeeo.com.
To enable us to analyze the situation quickly, please provide as much information as possible:
If the assessment reveals a risk to the rights and freedoms of the individuals concerned, Dipeeo, as an external DPO, will take the following actions:
1. 123456 🏆 (used 68,703 times in France and 3,018,050 times worldwide)
2. 123456789
3. AZERTY
4 qwerty123
6. azertyuiop
7. Marseille
8. comfort blanket
9. Loulou
10. 12345678
11. 1234561
12. 000000
13. favorite
14. password
15. sun
16. mypassphrase
17. 1234567
18. password
19. Nicolas
20. Camille
The risk:These weak and predictable passwords directly expose personal data to the risk of breach.
What the GDPR says GDPR Article 32 requires a level of security appropriate to the risk. A strong password is the first step in protecting personal data.
How can you improve your password compliance?
✔ Choose long, unique, and complex passwords (minimum 12 characters).
✔ Encourage the use of password managers
✔ Double your security with multi-factor authentication
✔ Regularly raise awareness about the importance of security in the context of the GDPR
Context:Mobile applicationsaccess a lot of sensitive data (location, health, contacts), increasing risks to privacy and security.
Objective of the CNIL (National Commission for Information Technology and Civil Liberties): To strengthen the protection of personal data in the field of mobile applications.
Target audience: Application publishers, developers, SDK providers, advertising agencies, platform managers, data controllers.
Penalties for non-compliance: Temporary suspension of data processing, formal notice, penalties ranging from €20 million or 4% of global annual turnover.
The main recommendations of the CNIL (National Commission for Information Technology and Civil Liberties) mobile applications
- Transparency and information:Provide clear information about the data collected, the purposes, and users' rights.
→Action:Update the privacy policy.
:Obtain explicit and easily revocable consentbefore collecting non-essential data. →Action:Implement compliant pop-ups or banners with clear accept/decline options.- Data minimization:Collect only data that is strictly necessary for the application to function.
→Action:Audit the data collected to identify actual needs.- Data security:Adopt technical and organizational measures to prevent unauthorized access and leaks.
- Accountability :All mobile players must collaborate to ensure GDPR compliance.
→Action:Verify your service providers' compliance and appoint a DPO.
"Define Data retention periods": this is one of the six key principles ofGDPR.
Once this period has elapsed, the data must be destroyed, anonymized, or archived securely.
- Resume and cover letter: 2years from the last contact with the unsuccessful candidate
- Pay slip:50 years or until the employee's retirement age and the following 6 years
- Identity card:Until the hiring is confirmed, then immediately destroyed
- Disciplinary sanction:3 years from the date of notification of the sanction
Available directly on theDipeeo platformby clicking on your profile in the top right corner.
Here you will find allthe answers to your questionsand the resources you need to get the most out of our services.
Now is the time to spread the word!
Refer a new client Dipeeo and receive adiscount on your monthly or annual subscription for1 year:
Good to know: If your discounts exceed the amount of your initial subscription, we will refund you the difference.