UK’s data protection authority – the Information Commissioner’s Office (ICO) published its guidance on the Lawful Basis for Processing Special Category Data, outlining the types of sensitive personal data that are recognised as special category data under Article 9 of the General Data Protection Regulation (GDPR) and how organisations should approach processing special category data, highlighting the nature of special category data, the applicable rules, and the conditions for processing such data under Article 6 of the GDPR.
Recommendations 2/2025 on the legal basis for requiring the creation of user accounts on e-commerce websites
The EDPB clarifies that mandatory user accounts are only lawful under the GDPR when they are strictly necessary and respect […]