The DPO role: Article 37(1)(b)

The DPO role: Article 37(1)(b)

members 5 min read
10 Oct: Estonia's thresholds for 'large-scale' (5k, 10k, 50k) | Breaking down Article 37(1)(b) key terms: 'core activities', 'regular', 'systematic', 'monitoring' and 'large scale'. And what should you do if you're still unsure whether you need to appoint a DPO? Appoint one voluntarily?
CJEU C-655/23 Quirin Privatbank 4 Sep 2025

CJEU C-655/23 Quirin Privatbank 4 Sep 2025

members 3 min read
GDPR offers no judicial remedy outside erasure requests to stop future unlawful processing, but Member States may. Non-material damage covers negative feelings – if proven. A controller’s fault doesn’t affect compensation, and a court order banning repeat GDPR violations can’t reduce or replace it.
CJEU C-383/23 ILVA (GDPR fine) 13 Feb 2025

CJEU C-383/23 ILVA (GDPR fine) 13 Feb 2025

members 4 min read
2 Sep: 💸 ILVA fined €201k | When fining a controller in a corporate group, DPAs must base the maximum fine on the *group’s* total worldwide turnover from the prior business year. A crucial ruling for anyone in a company group – here's also text you can copy for an email to your Management/Board.
Welcome! Start here 👇

Welcome! Start here 👇

members 2 min read
Bumping this as reminder – to make the most out of your subscription, read through this post: How to use DPO Hub effectively and find your way around.