Issue 326

  • India’s SEBI fined a central securities depository INR 10 million for cybersecurity failures following its 2022 malware attack.
  • South Korea’s data authority sanctioned a social media and a tech giant for processing personal information without a valid lawful basis.
  • China’s CAC launched public consultation on revised draft administrative measures for internet information services.
  • Singapore’s PDPC issued guidance on the responsible use of personal data in generative AI systems.
  • Vietnam government approved its National Digital Transformation Strategy for 2026 – 2030.
  • The European Commission imposed EUR 890 million fine on a technology company for violation of the Digital Markets Act.
  • UK’s Department of Science, Innovation and Technology launched a call for evidence on its approach to international data transfers.
  • France’s CNIL and the Council for AI and Digital Technology published an exploratory note on agentic AI and personal data. 
  • The European Data Protection Board called for a legal basis for information sharing between regulatory authorities.
  • Italy’s National Cybersecurity Agency updated its FAQs on the obligations of administrative and management bodies.
  • Austria’s Supreme Administrative Court confirmed unlawful processing of political-affinity data and imposed a fine of EUR 1.3 million
  • The European Commission published guidelines on transparency obligations under Article 50 of the AI Act.  
  • Spain’s AEPD and Competition Commission published an article examining addictive design and digital platforms.  
  • Polish Financial Supervisory Authority issued recommendations for financial market entities on cybersecurity risks arising from frontier AI models.
  • The EU Commission and Cybersecurity Agency signed a contribution agreement to support the health sector in strengthening cybersecurity defences.
  • Kenya’s MICDE launched public consultation on the draft AI and Emerging Technologies Policy.
  • The FTC filed a lawsuit against a telehealth provider over the alleged sharing consumers’ health information to advertising platforms.
  • The US Supreme Court ruled that obtaining location history data through a geofence warrant constitutes a Fourth Amendment search.
  • New York’s Attorney General and Governor issued final rules implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act.
  • California’s CalPrivacy launched its first sectoral privacy audit, targeting gig economy platforms.
  • Illinois enacted a legislation establishing safety and transparency obligations for frontier AI developers.
  • New Jersey postponed the enforcement of its data broker registration requirements until 2027.
  • Brazil’s ANPD published a Technology Radar report examining deepfakes and their data protection implications.
  • Twenty-nine countries signed an agreement establishing the World AI Cooperation Organization.
  • South Korea’s PIPC announced that that the European Commission renewed the adequacy decision for the Republic of Korea under the GDPR