EU & UK
- Privacy authorities for Canada and the United Kingdom to announce findings of joint investigation into global data breach at 23andMe.
- Finland’s Ombudsman requested organisations to update DPO contact information.
- Turkey’s KVKK announced that it will now issue data protection fines via the Revenue Administration’s E-Notification System, per a new protocol with the Treasury Ministry.
- Netherlands’ data protection watchdog hasreduced its fine against health and beauty retailer AS Watson by over 90%.
- The Norwegian DPA, Datatilsynet, fined Kristiansand Municipality NOK 250,000 for GDPR violations related to tracking pixels on the Alarmphone website.
- The CNIL has requested public comments on draft recommendations regarding tracking pixels in emails, emphasising the need for recipient consent for various tracking purposes.
AMERICAS
- A recent media report detailed that Meta is planning to overhaul its risk assessment program, including removing review personnel in favour of AI automation.
- Oregon A.G. joined 28 other state attorneys general in a bipartisan lawsuit opposing the sale of genetic data by bankrupt firm 23andMe.
- Nebraska’s A.G. sued online marketplace Temu for allegedly unlawfully harvesting data and using deceptive practices to encourage purchases.
- Several major U.S. airlines allegedly sold access to consumer flight data to the U.S. Department of Homeland Security.
- A U.S. court in California denied class-action status in a case alleging Google collected Chrome users’ data without consent.
ASIA PACIFIC
- New Zealand’s Privacy Commissioner issued guidance confirming the Privacy Act 2020 applies to clubs and societies that collect personal information.
- The National Privacy Commission issued guidelines for processing personal data collected via body-worn cameras, emphasising lawful processing, security, and data subject rights.
