Issue 322

  • The Reserve Bank of India published draft guidance outlining regulatory expectations for data governance across regulated entities.
  • South Korea’s PIPC fined a cryptocurrency exchange KRW 210 million for unlawful overseas transfers of personal data.
  • Japan’s House of Representatives passed a bill amending the Act on the Protection of Personal Information.
  • Singapore’s Cyber Security Agency published its Singapore Cyber Landscape 2025/2026 report highlighting key cybersecurity threats and trends.
  • Vietnam adopted a business ethics and culture framework incorporating principles on AI governance and data protection.
  • The European Commission ordered a technology company to restore competing AI assistants’ free access to its messaging platform.
  • UK’s ICO fined a debt management company GBP 300,000 for sending multiple unlawful marketing messages.
  • Italy’s Cybersecurity Agency updated its guidelines on cryptographic functions and secure cryptographic implementations.
  • The Court of Justice of the European Union ruled that courts may consider unlawfully obtained personal data as evidence under certain conditions.
  • Denmark’s Datatilsynet urged organisations to reassess transfers of personal data to the United States following the Trump v. Slaughter ruling.
  • Ireland’s Government published the Regulation of Artificial Intelligence Bill 2026 to implement the EU AI Act.
  • The Dutch Data Protection Authority launched a public consultation on a proposed list of processing activities exempt from DPIA.
  • The European Parliament approved measures simplifying certain requirements under the AI Act.
  • Turkey’s KVKK issued guidance on the privacy implications of municipal live broadcasts used for tourism promotion.
  • U.S. Senators introduced the Stop Spying Bosses Act to regulate electronic surveillance of workers.
  • Five Eyes cybersecurity agencies published a joint statement on managing cybersecurity risks associated with AI.
  • The U.S. Office of Civil Rights reached a USD 450,000 settlement with a health plan company over HIPAA violations following a ransomware attack.
  • New York’s law requiring disclosure of synthetic performers in advertisements came into effect.
  • Canada introduced Safe Social Media Act to strengthen protections against harmful content on online platforms and AI chatbots.
  • Delaware Legislature passed a bill amending the Personal Data Privacy Act.
  • Colorado’s AG invited comments on proposed rules governing automated decision-making technologies and chatbot safety.
  • The U.S. Senate Judiciary Committee advanced the James T. Woods Act to combat online child exploitation.
  • Ecuador’s SPDP launched a public consultation on proposed reforms governing the processing of personal data through AI systems.
  • Vermont’s Governor signed legislation strengthening consumer data privacy and regulating online surveillance.
  • Costa Rica’s SUTEL proposed strengthened regulatory measures to protect users against malicious text messages and digital fraud.