Issue 256

  • Dutch AP requested feedback on tools for human intervention in algorithmic decision-making.
  • Luxembourg’s CNPD issued a reminder on consent as a condition of lawfulness requirements under GDPR.
  • EDPB initiated a Coordinated Enforcement Framework (CEF) action to investigate the implementation of the right to erasure under Article 17 of the GDPR.
  • Loan comparison provider Sambla Group issued an administrative fine for data security neglect.
  • The AEPD fined LaLiga Group International, S.L. EUR 1 million for not conducting a DPIA before implementing biometric access controls in football stadiums.
  • Icelandic SA imposed an administrative fine on the Primary Health Care for the unlawful processing in relation to the integration of medical record systems.
  • NIST finalised its guidance on evaluating the use of differential privacy techniques to protect sensitive personal data contained in large datasets.
  • California AG announced an ongoing investigative sweep into the location data industry that appears to be in violation of the CCPA.
  • Saturn Technologies, agreed to pay USD 650,000 in penalties after it failed to verify users’ identities, potentially exposing students’ personal information to strangers.
  • California’s Senate Bill 7, concerning the use of automated decision systems (ADS) in employment, passed its second reading with amendments on March 6, 2025.
  • Telstra fined for SMS spam as Australia moves to establish SMS Sender ID Register.
  • TC260 requested comments on competency requirements for personal information protection auditors.