Issue 248

  • CJEU ruled on Case C-416/23, stating that ‘excessive’ access requests under GDPR cannot be deemed so just by their number, emphasizing intent over quantity.
  • CJEU ruled that gender identity is not necessary data for the purchase of a transport ticket.
  • Datatilsynet critiqued proposed changes to Norway’s Health Research Act, emphasising data protection concerns.
  • EDPS reprimanded Frontex for unlawfully sharing the personal data of cross-border crime suspects with Europol, violating the Frontex Regulation. 
  • CJEU ordered the Commission to pay 400 EUR for the unlawful transfer of personal data.
  • NY’s Senate Bill 7676B regulated contracts for digital replicas, requiring specific use descriptions and legal representation.
  • Utah’s House Bill 124, filed in January aims to protect the privacy of education industry employees by prohibiting the sale or transfer of their work-related contact.
  • Senate Bill 7676B for an Act entered into force to amend the general obligations law concerning contracts for the creation and use of digital replicas entered into force.
  • Washington AG sued T-Mobile for a data breach affecting millions and inadequate response.
  • China’s new regulations mandate enhanced data security measures and transparent processing of personal information.
  • India’s MeitY released draft data protection rules detailing consent, data fiduciary obligations, and a public comment period till February 18, 2025.