Issue 316

  • The Securities and Exchange Board of India issued an advisory on cybersecurity risks associated with advanced AI-powered vulnerability detection tools.
  • China’s Ministry of Industry and IT released a national classification standard for AI terminals, establishing intelligence levels and evaluation criteria.
  • Australia’s Office of Information Commissioner published updated guidance on the collection of solicited personal information.
  • Vietnam’s government approved the National Standards Strategy for 2026-2035.
  • South Korea’s PIPC fined a funeral services company KRW 553.9M for a personal data breach and failures to implement adequate security measures.
  • The European Data Protection Board published an opinion on Finland’s proposed accreditation requirements for GDPR certification bodies.
  • UK’s ICO fined a water services company GBP 963,900 for data security failures following a cyberattack and personal data breach.
  • Germany’s BfDI and partner authorities released a roadmap clarifying the application of EU AI Act for AI-enabled medical devices.
  • France’s CNIL published recommendation on use of personal data for creditworthiness assessment, including guidance on automated decisions.
  • The EU Council and Parliament reached a provisional agreement to streamline certain rules in the EU AI Act.
  • Ireland’s DPC imposed EUR 277,500 fine on a bank for data security deficiencies and failure to timely notify personal data breaches.
  • Belgium’s DPA fined a fintech company EUR 120,000 for incorrectly classifying itself as a data processor and failing to meet data controller obligations.
  • The European Commission adopted a recommendation establishing an EU-wide framework for age verification technologies.
  • Poland’s Ministry of Digital Affairs notified entities of new compliance obligations under the amended National Cybersecurity System Act.
  • Turkish Data Protection Authority publishes a data breach notification involving a hospitality company.
  • The U.S. Federal Trade Commission urged companies ensure compliance with the Take It Down Act.
  • Colorado Legislature advanced amendments to the Colorado AI Act, refining compliance requirements for high-risk AI systems.
  • Brazil’s ANPD published preliminary guidance and implementation timeline for age verification under the Digital ECA framework.
  • California’s AG secured USD 12.75 million settlement with an automotive manufacturer over the unlawful sale of drivers’ location and driving data.
  • The U.S. Cybersecurity and Infrastructure Security Agency launched CI Fortify initiative to strengthen resilience of critical infrastructure.
  • Texas’ AG sued a streaming platform over alleged deceptive data collection practices, privacy misrepresentations and unlawful user profiling.
  • Illinois’ Senate Committee passed a bill on AI safety measures, establishing governance, transparency and audit requirements for frontier AI models.