Issue 280

  • EDPB adopted an opinion on the interplay between the Digital Services Act and the GDPR.  
  • ICO published clarifications addressing myths related to storage and access technologies.
  • The EU’s Data Act has officially become applicable
  • Hamburg Data Protection Authority released a draft paper on the GDPR and the AI Act.
  • Finland’s the Data watchdog fined a Bank EUR 1.8M for vulnerability in authentication process. 
  • In Estonia, the Data Protection Inspectorate fined Med-tech EUR 3M for failing to protect customer data.
  • The California State Legislature passed the “Opt Me Out Act.”
  • FTC launched an inquiry into AI chatbots and their role as digital companions.  
  • The California Privacy Protection Agency, with the AG of California, Colorado, and Connecticut, to investigate noncompliance of the Global Privacy Control.   
  • The Alberta OIPC issued guidance for use of AI tools under the Health Information Act.
  • Personal Information Protection Commission of South Korea fined a fashion brand KRW 80.1 million for violations of PIPA.   
  • The Indian IT Minister confirmed that Digital Personal Data Protection Rules will be published by September 28, 2025.