Issue 205

EU

  • Italian data protection authority imposed a fine of EUR 100,000 on Autostrade per l’Italia S.p.A. for violations of the General Data Protection Regulation.
  • Icelandic data protection authority imposed a fine of ISK 3 million on Kópavogur Municipality, for violations of the Act on Privacy and Processing of Personal Data and the General Data Protection Regulation.
  • Belgian Data Protection Authority ordered the Diocese of Ghent to comply with the request of a baptized person to be deleted from the baptismal register.
  • European Commission published draft pledging principles for the use of cookies. 

AMERICAS

  • The California Privacy Protection Agency announced that data brokers must register annually starting on January 1, 2024.
  • Québec provincial government proposed a draft regulation on the anonymization of personal information. 
  • The Federal Trade Commission proposed amendments to the Children’s Online Privacy Protection Act Rules and is seeking public comments on the same. 

ASIA PACIFIC

  • South Korea’s Personal Information Protection Commission revised its Exposure Prevention Guide for Personal Information on Websites. 
  • Ministry for Science and ICT and the Korean Internet and Security Agency signed a Memorandum of Understanding with the Singaporean Cyber Security Agency regarding the mutual recognition of Internet of Things security certification systems.
  • China’s Ministry of Industry and Information Technology (MIIT) published a notice of its ninth batch of notifications to apps on violations of users’ rights in 2023.
  • MIIT requested public comments on the draft Emergency Plan for Data Security Incidents in the Industrial and Information Technology Fields.

Read our digital newsletter here.