Issue 323

  • G7 data protection and privacy authorities issued a joint statement on privacy-preserving age assurance.
  • NOYB published a statement analysing the implications of the Trump v. Slaughter ruling for transfers of personal data from the EU to the United States.
  • China’s State Administration for Market Regulation released national standards for AI agent interconnection and interoperability.
  • Singapore’s Ministry of Digital Development and Information published regulations governing end user identity verification for online safety.
  • Vietnam’s legislations on digital transformation and high technology came into force.
  • South Korea’s PIPC revised its guidance on right to request transmission of personal information across sectors.
  • Australian government proposed stronger enforcement powers and higher penalties under its social media minimum age law.
  • European Data Protection Board launched a public consultation on draft guidelines addressing web scraping in the context of generative AI.
  • Italy’s Competition Authority launched an investigation into a technology company’s compliance with DMA interoperability requirements.
  • Spain’s Cryptologic Centre published guidance on responding to offensive AI threats and strengthening organisational cyber resilience.
  • Poland’s UODO issued guidance on unlawful personal data processing through deepfakes technologies.
  • European Data Protection Supervisor published a checklist on human intervention in automated decision-making.
  • Portugal‘s National Communications Authority opened a public consultation on draft recommendations for implementing Article 5 of the EU AI Act.
  • Ireland’s Cyber Security Centre released cybersecurity guidance for secure AI adoption in the public sector.
  • European Union’s NIS Cooperation Group published reference document on security measures for operators of essential services.
  • Romania’s Communications Authority launched a public consultation on draft legislation implementing the EU Data Act.
  • The U.S. House of Representatives passed the amended KIDS Act, strengthening children’s privacy and online safety protections.
  • California’s AG secured a ruling denying a technology company’s motion for summary judgment in a child safety lawsuit.
  • New Jersey enacted legislation requiring data broker registration and restricting sale of sensitive health information.
  • Canadian government introduced the Protecting Privacy and Consumer Data Act to modernise private sector privacy protections.
  • Virginia’s legislation on automatic renewal and continuous service offer requirements for subscriptions came into force.
  • Montana’s amendments to electronic health records law came into effect.
  • Vermont’s Governor signed legislation strengthening privacy protections for consumers’ genetic data.
  •  The Ibero American Data Protection Network adopted a reference document on neurodata processing in non-medical sectors.