Issue 324

  • India advanced its Safe and Trusted AI initiative by supporting responsible AI projects and establishing the IndiaAI Safety Institute.
  • South Korea’s PIPC proposed expanding personal data portability rights to the education and employment sectors.
  • China’s financial regulators launched a public consultation on draft cybersecurity measures for the financial industry.
  • Vietnam’s government issued a list of high-risk AI systems and established transitional compliance deadlines for existing systems.
  • Australia’s OAIC published a quick reference guide for responding to data breaches.
  • The European Commission adopted a proposal for AI Continent regulation, to promote research and expand secure processing capacity.
  • France’s CNIL published findings from a survey examining the impact of AI and the EU AI Act on Data Protection Officers.
  • ICO, UK fined a home improvement company GBP 240,000 for making unlawful direct marketing calls. 
  • Italy’s Garante imposed a fine of EUR 158,000 on a chatbot platform for failing to protect minors and implement age verification measures.
  • The European Data Protection Board launched public consultation on its guidelines related to data anonymisation.
  • Netherlands’ Senate approved the Cybersecurity Act and Critical Entities Resilience Act, implementing the European Critical Entities Resilience Directive.
  • Hungary’s NAIH issued a statement concerning the use of children’s personal data for political purposes on social media.
  • EU Commission presented an action plan addressing the risks and opportunities of advanced AI in cybersecurity.
  • Slovenia’s Information Commissioner issued an opinion on assessing biometric data processing for identity verification.
  • Mozambique’s INTIC published the Cybersecurity and Cybercrime Laws in the Official Gazette.
  • The European Parliament supported a narrower ePrivacy derogation for voluntary detection of online child sexual abuse.
  • The U.S. President signed an Executive Order securing the country against advanced cryptographic attacks.
  • New Jersey’s Fair Price Protection Act, restricting the use of personal data for surveillance pricing, passed by the Legislature.
  • Virginia amended its Consumer Data Protection Act to prohibit the sale of precise geolocation data.
  • Hawaii’s Governor signed legislation establishing safeguards for deepfakes and AI companion services.
  • South Dakota’s genetic data privacy law came into effect, introducing obligations for genetic testing companies.
  • Florida’s AG reached a resolution with a streaming platform requiring enhanced parental controls and safeguards for children’s personal data.
  • New Hampshire enacted legislation prohibiting the sale of children’s personal data.