Issue 303

  • The Indian government launched Strategy for AI in Healthcare for India (SAHI) and Benchmarking Open Data Platform for Health AI (BODH) at the India AI Summit.
  • China’s Technical Committee 260 invited comments on draft national standard for data security for professional institutions conducting personal information protection compliance audits.
  • Electronic Transactions Development Agency, Thailand launched consultation on draft AI data protection guidelines.
  • The State Bank of Vietnam initiated a consultation on regulations governing safety, risk management and conditions for deploying AI in banking sector.
  • European Data Protection Board and Supervisor issued a joint opinion on Digital Omnibus regulation.
  • UK Information Commissioner’s Office published guidance for organisations on handling the data protection complaints.
  • France’s CNIL released report on its enforcement actions in 2025, including sanctions and corrective measures.
  • German data authority initiated a consultation on data protection-compliant information handling in AI models.
  • Italy Data Protection and Labour authorities launched joint investigation into an e-commerce company’s logistics centers for worker surveillance practices.
  • AEPD, Spain issued warning to a technology company over resumption of biometric data processing operations.
  • European Data Protection Supervisor introduced new guidance and binding rules to safeguard independence of Data Protection Officer in EU institutions.
  • Belgian Financial Markets Authority released updated process and timeline for collection of information registers under Digital Operational Resilience Act.
  • The Data Protection Commission, Ireland launched investigation into a social media company for creation and publication of non-consensual, AI-generated images.
  • Dutch Data Protection Authority warned about privacy and security risks associated with the use of AI agents.
  • Czech Office for Data Protection launched a public consultation on camera systems located at healthcare providers.
  • Guernsey Data Authority released new resources for data protection professionals.
  • European Commission introduced new toolbox to boost ICT supply chain security.
  • The Electronic Privacy Information Center urged the US FTC and state enforcers to block a technology company’s plan to add facial recognition to smart glasses.
  • US Department of Labour released a framework to improve AI literacy across public workforce and education systems.
  • California Attorney General filed a lawsuit against El Cajon city for sharing automated license plate reader data unlawfully.
  • South Carolina became the fifth US state to approve law on age-appropriate design code.
  • Texas Attorney General filed a lawsuit against social media company over children’s safety concerns.
  • Kentucky Kids Code, a bill requiring online services to apply the highest default privacy protections for minors introduced in House of Representatives.
  • Brazil’s Data Protection Agency, Public Prosecutor’s Office and Consumer Secretariat jointly recommended a social media platform to enhance safety measures for its AI chatbot.
  • Egypt’s Data Protection Centre published guidelines and official templates to implement the personal data protection law.
  • Data Protection Commission, Nigeria launched an investigation into an online marketplace for data protection violations.
  • Saudi Data and AI Authority released regulations on issuance of accreditation certificates to controllers and processors.