Issue 304

  • The Supreme Court of India emphasised that public interest cannot justify unrestricted access to private data.
  • Unique Identification Authority of India launched a Bug Bounty Programme aimed at strengthening the security of Aadhaar ecosystem.
  • China’s Ministry of Industry and IT launched consultation on five mandatory standards for automated driving systems.
  • The Australian Cybersecurity Centre published guidance on cybersecurity risks associated with quantum computing.
  • EU Commission initiated an investigation into an online clothing retailer under the Digital Services Act.
  • Cybersecurity Authority of Italy introduced new taxonomy defining the types of incidents that trigger notification obligation.
  • France’s Council of State upheld the fines imposed by CNIL on three healthcare technology companies.
  • A bill on information exchange between law enforcement agencies of EU member states published in the official gazette of Germany.
  • European Data Protection Board adopted Coordinated Enforcement Framework report on challenges in implementation of the right to erasure.
  • AEPD, Spain released guidance on the data protection implications of using agentic AI.
  • Italian privacy authority approved the use of patients’ telephone numbers for screening campaigns.
  • UK Court of Appeal upheld the ICO’s appeal in a data breach case involving a consumer electronics retailer.
  • The European Banking Authority released updated Q&A on Digital Operational Resilience Act.
  • The Faroe Islands Data Protection Authority recommended a fine of ISK 14 million against the national airline for insufficient technical and organisational safeguards.
  • U.S. Institute of Standards and Technology announced AI Agent Standards Initiative to ensure secure and interoperable AI ecosystem.
  • A bill reducing data broker deletion request timeline introduced in California Senate.
  • Texas Attorney General filed a lawsuit against an online shopping platform for deceptive marketing and illegal data harvesting.
  • New York bill for the protection of health information, requiring written consent or designated purpose for processing health information introduced in Senate.
  • Oklahoma comprehensive data privacy law passed by both the houses.
  • Kansas Senate passed the App Store Accountability Act, to regulate app store and developer operations to enhance protections for minors.
  • California bill restricting wearable recording devices in private areas of businesses introduced in Senate.
  • Crown Dependency Data Protection Authority issued guidance on generative AI image creation.
  • Global Data Protection Authorities issued joint statement on AI-generated imagery and protection of privacy.