Issue 199

EU & UK

  • UK’s Office of Communications announced that the Online Safety Act had become law after receiving Royal Assent.
  • European Commission concluded an agreement with Japan focused on cross border data flows.
  • European Data Protection Board extended the ban on the processing of personal data for the purpose of behavioral marketing carried out by Meta Platforms Ireland Limited on its Facebook and Instagram platforms to the entire EU/EEA area.
  • UK’s Department of Science, Innovation and Technology published the first phase of an evaluation of the implementation of the International Data Transfer Agreement.

AMERICAS

  • U.S. Department of Health and Human Services Office for Civil Rights announced a USD 100,000 settlement with Doctors’ Management Services Inc. for potential violations of the Health Insurance Portability and Accountability Act Privacy and Security Rules, following a ransomware attack.
  • U.S Congressmen introduced a bill titled ‘Facial Recognition Act 2023’ in the House of Representatives.
  • Governor of New York announced that the New York State Department of Financial Services had made amendments to its cybersecurity regulation to introduce stronger standards and controls to secure data.
  • Quebec Commission on Access to Information published final guidelines on criteria for the validity of consent. 

INDIA AND ASIA PACIFIC

  • Australian Communications and Media Authority announced that Kmart Australia Limited had paid an infringement notice of AUD 1.3 million for violation of the Spam Act 2003.
  • Queensland Government introduced the Information Privacy and Other Legislation Amendment Bill 2023 to the Queensland Parliament.
  • Asia Internet Coalition sent a letter to India’s Ministry of Electronics and Information Technology, containing a list of recommendations for an increased timeline for the implementation of certain provisions of the Digital Personal Data Protection Act, 2023 and the rules and regulations thereunder.
  • China’s Ministry of Transport published the personal data file security maintenance plan and handling measures for the motor transport industry.