Suor Orsola University Press - Open Science
Not a member yet
1271 research outputs found
Sort by
Compliance evaluation
Case Study The ACME bank has recently developed a new business line consisting of the direct offer of insurance products placed on behalf of a commercial partner. The signing of the policy documents takes place in the branch through the use of the FEA and the documents signed in this way are sent directly to substitutive storage with a third-party supplier that operates both on behalf of the bank and on behalf of the insurance company. The management process requires that all documents provided by customers are digitized for forwarding to the insurance company and that the original document is forwarded directly to the external service of the same company. Similarly, claims management takes place by collecting all the documents that are digitized directly in the branch office. The operations are carried out using a software application made available by the Company and branch operators access it through specific credentials issued by the latter
Data Security and University Widening Participation Services
You are working as an assistant DPO in a large Post-92 University. Universities in the UK are encouraged to widen participation in Higher Education from groups that are traditionally less represented in HE. As such, the Widening Participation team have been working with local schools and undertaking events with children, including those from groups that are less represented in HE. Where these are sixth form students they are often invited into the University and WP team keep a register of these young people so that they can track the effectiveness of their outreach activities by surveying the young people to see how many were applying to University and the different Universities they applied to. Your task is to advise on what data that is currently stored should be kept and used and what arrangements can be made into the future to ensure the effectiveness of these activities
How legal design can improve data protection communication and make privacy policy more attractive
This article addresses the problem of communication of privacy policies, usually written by lawyers for lawyers using complex language and technical legal terms (so-called “legalese”). As such, data subjects barely read them or are not able to fully understand their meaning. In this scenario legal design may offer innovative solutions to draft and communicate more accessible and efficient privacy notices. In particular, legal design draws on the application of design mindsets and methodologies to the legal environment in order to make it more creative, communicative and user-centered
Antonacci F., Gambacorti-Passerini M.B. & Oggionni F. (a cura di), Educazione e terrorismo. Posizionamenti pedagogici, Milano: FrancoAngeli, 2019, pp. 151.
Save the Children, Riscriviamo il futuro. Rapporto sui primi sei mesi di attività. Dove sono gli adolescenti? La voce degli studenti inascoltati nella crisi, Roma: Save the Children, 2021, pp. 32.
Sentencias del Tribunal Supremo Sala de lo civil 210/2016 de 5 de abril ECLI:ES:TS:2016:1280
Vendor Risk Management and Data Protection Agreement negotiation
Ego’ is an Italian cosmetic company headquartered in Milan. It focuses on hair colour, skin care, sun protection, make-up, perfume, and hair care. Its Head of Marketing, Jane, is currently working on a new web campaign to advertise Ego’s brand new green tea mask: her plan is to create a website where people can purchase the new product or simply subscribe a newsletter to receive exclusive offers and the latest news on Ego’s products. To run this campaign, Jane decides to use a Software as a Service (SaaS) solution named ‘Bazaar’, i.e., a US e-commerce platform for online stores and retail point-of- sale systems. As such, she contacts all the relevant internal stakeholders (i.e., Procurement, InfoSec, and Privacy) to get the new Vendor on boarded sooner
Sentencia del Tribunal Supremo (Sala 3a de lo Contencioso Administrativo), sts 3896/2014, ECLI: ES:TS:2014:3896
Promusicae (entidad privada) solicitó a la AEPD al amparo del artículo 5.5 de la LOPD, la exención del deber de informar a los usuarios de redes peer to peer (P2P) del tratamiento de datos que dicha entidad privada pretendía llevar a cabo para el ejercicio de defensa de los derechos de propiedad intelectual de los productores y editores de fonogramas y videos musicales. Esencialmente, Promusicae pretendía recabar las direcciones IP de los usuarios que accedían a esas redes P2P y se descargaban determinados contenidos digitales para posteriormente poner a disposición de las autoridades correspondientes dichas direcciones IP de cara a emprender acciones judiciales contras las personas que se descargaban y compartían tales contenidos
Legal design and artificial intelligence in support of legislative drafting during crisis
During the emergency period of the coronavirus, numerous legislative acts have been issued in Italy, the content of which is full of references to other measures, long and complex periods that are incomprehensible to citizens. These measures have revealed a lack of legislative drafting, in which the methodology of legal design can be a remedy
Sentencia del Tribunal Supremo, Sala de lo Civil 267/2014 de 21 de mayo, ECLI:ES:TS:2014:2040
D. Gerardo, abogado en ejercicio, llevó a cabo en el año 2008 un contrato con la empresa “Yell” para obtener publicidad en las páginas amarillas acerca de su actividad profesional. Meses más tarde, hace uso de la facultad de desistimiento unilateral recogida como cláusula en el contrato para poner fin a dicha relación contractual, en este sentido, se lo comunica a la empresa a través de la dirección de correo electrónico destinada a la comunicación con clientes. En dicha comunicación, hizo constar que se le cargaran en su cuenta las respectivas cantidades referentes al tiempo en que el contrato estuvo vigente. Sin embargo, Yell hizo caso omiso de la misma, y aun recibiendo nueva comunicación del demandante, no atendió a dicha comunicación. Acto seguido, y sin previo requerimiento previo, comunicó los datos del aquí demandante al fichero de solvencia patrimonial “Asnef” del que es responsable del fichero “Equifax”. “Equifax” remitió una comunicación al demandante para comunicar dicha inclusión, pero la misma fue devuelta. El demandante, cuando tuvo conocimiento de dicha inclusión, remitió comunicación a “Equifax” para la cancelación de sus datos respectivos. A pesar de ello, denegó dicha cancelación al alegar que los datos fueron ratificados por “Yell”. El demandante procede a interponer la demanda correspondiente por intromisión de sus derechos del artículo 18.1 y 4 CE, y lo recogido en la LO 1/1982 de 5 mayo de protección de los derechos al honor, intimidad y propia imagen, además de la LO 15/1999 de protección de datos de carácter personal. Sin embargo, en instancias previas se desestimaron las pretensiones previas contra la empresa “Equifax”