Issue 247

  • The Dutch Data Protection Authority (AP) fined Coolblue B.V. EUR 40,000 for GDPR violations related to improper cookie consent practices. 
  • France’s new law enforced DSA and DMA, focusing on minor protection, fair data transfer fees, and service interoperability.
  • Italian Regulator issued EUR 15M fine to OpenAI for GDPR infractions.
  • Poland’s data protection authority fined the rental car company Panek for not putting appropriate data processing security measures in place when it reconstructed its company website.
  • An investigation by Der Spiegel found several terabytes of data for approximately 800,000 electric Volkswagen vehicles were left unprotected in an Amazon Cloud system for several months.
  • The US Department of Health and Human Services (HHS) has proposed updating the Security Rule under the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
  • The California Privacy Protection Agency (CPPA) has settled with two further data brokersunder the state’s Delete Act.
  • Oregon DoJ’s issued advisory on AI stresses OCPA compliance, explicit consent for data use, and consumer rights.
  • Indian Home Ministry approved the Data Protection Rules, and its release is anticipated soon for public consultancy.
  • Thailand’s PDPC opened thePersonal Data Protection Act for review.
  • Japan’s prime minister discussed plans to strengthen AI safety and use of data.