Issue 320

  • Reserve Bank of India directed banks to conduct board-approved gap assessment on AI cybersecurity risks and develop mitigation plans.
  • South Korea’s PIPC published research and standardization roadmap for personal information lifecycle protection and utilization.
  • Thailand’s Electronic Transactions Development Authority announced AI 2026 strategy to strengthen trust in AI governance.
  • Vietnam’s Department of Telecommunications introduced facial re-authentication requirements for mobile subscribers changing devices.
  • The European Commission published its report on the implementation of the Digital Markets Act.
  • UK’s ICO provided advice to the government on proposed changes to online advertising consent rules.
  • France’s CNIL issued guidance on compliance requirements for electronic communications with prospects and clients.
  • Germany’s Bundestag approved legislation implementing the EU AI Act and establishing AI market oversight framework.
  • Ireland’s DPC fined Health Service Executive EUR 300,000 for GDPR security failures following a ransomware attack.
  • Spain’s Parliament published draft Organic Law establishing AI governance framework and sanctions regime.
  • Norway’s Datatilsynet imposed NOK 20 million fine on an electronics retailer for processing customer club data without valid consent.
  • Netherlands’ AP published 2025 complaints report highlighting sharp rise in privacy complaints.
  • Croatia’s AZOP launched EDPB coordinated enforcement action on GDPR transparency obligations.
  • The United States published the draft Great American AI Act to advance AI innovation, cybersecurity and secure frontier model deployment.
  • New York’s bill on Health Information Privacy Act passed by the legislature.
  • Texas’ AG secured restraining order requiring a technology company to strengthen default child safety settings.
  • Vermont bill regulating data brokers and personal information passed by the legislature.
  • Connecticut’s Governor signed the Online Safety Act, introducing enhanced protections for young users and safeguards relating to artificial intelligence.
  • Canada Government published National Artificial Intelligence Strategy outlining commitments on AI adoption, safety and digital sovereignty.
  • CalPrivacy together with a coalition of AG opposed the SECURE Data Act over privacy concerns.
  • Colorado enacted law establishing requirements and safeguards for conversational AI services.
  • Illinois legislature passed the Children’s Online Social Media Safety Act introducing default protections for minors.
  • Brazil’s ANPD began monitoring app stores and operating systems for compliance with the Digital Statute for Children and Adolescents.
  • EU and South Korea signed a Digital Trade Agreement to strengthen digital trade, cross-border data flows and consumer protection.
  • Slovenia’s Information Commissioner issued opinion on personal data transfers to the United States under the GDPR.