data protection news

The EU’s AI Act addresses risk categories, while the ICO is addressing data rights in real-time autonomous decision-making. The startups most at risk are those treating compliance as a post-launch exercise. The DRCF’s cross-regulatory paper signals that UK and EU approaches, while structured differently, are converging in substance around transparency, accountability and risk controls. This is https://higgertylaw.ca/blog/what-ethical-guidelines-govern-lawyers-use-of-generative-ai especially important for products interacting with large numbers of people or vulnerable consumers. The CMA guidance makes clear that regular human-led reviews of agent performance are expected, and that where an agent is producing non-compliant results, traders must address that promptly.

This action marked the first time the agency claimed that a company’s use of AI was “unfair” and provided an early example of the FTC’s developing approach to enforcing consumer protection in the age of AI. Notably, UK-based Avast serves as a reminder to multinational companies that their data practices outside the US could still fall within the FTC’s enforcement authority. The Act classifies AI systems according to risk—unacceptable risk, high risk, limited risk, and minimal risk—and imposes requirements accordingly. The EU AI Act, considered the world’s first comprehensive legal framework for AI, introduced a risk-based approach to AI regulation and set out rules on data quality, transparency, human oversight, and accountability. In July, the European Commission, US Department of Justice, US Federal Trade Commission, and UK Competition and Markets Authority released a joint statement highlighting the benefits and risks of AI to competition, innovation, and consumers.

data protection news

For many organisations, particularly those handling customer, employee or online user data, these changes go beyond compliance on paper. Request a demo with one of our product experts to see why thousands of organizations choose Secureframe can to simplify compliance and safeguard their data. 2025 is the first year in which a majority of organizations (66%) of organizations said they use purpose-built technology to manage http://articlesss.com/keys-to-improved-master-data-management-and-product-information-management/ compliance risk in Navex Global’s annual State of Risk & Compliance Report. With new data protection rules, expanding supply chain obligations, and increasing enforcement pressure, preparation is essential.

Sign up for Data Protection News and Trends

The Dutch DPA’s position on using scraped data for training AI systems is not very clear. This fine therefore does not seem to be the direct result of the Dutch DPA’s crackdown on misleading cookie banners announced earlier this year. The Dutch Data Protection Authority has imposed a fine of EUR 600,000 on AS Watson, the company behind Dutch pharmacy retail chain Kruidvat. They may be accessing payroll tools, HR platforms, shared drives, internal documents, and email, sometimes on home networks or while travelling. Policies, retention practices, access controls, complaint handling, and internal training all need periodic review if they are going to remain defensible. The ICO says the Data Use and Access Act 2025 makes changes to data protection law that may affect organisations using personal information and has published a preparation checklist to help them get ready.

I enjoy providing practical advice and solutions to complex legal issues. The biggest fine imposed by the DPC last year was a €530 million penalty on TikTok for the transfer of the personal data of European users to China. “At the same time, the scale and complexity of the use of personal data by rapidly advancing AI technologies increased significantly, with heightened risks and harms for individuals,” he said. Like national security, children’s privacy tends to be an issue that garners support from both sides of the aisle and continues to generate regulatory interest at both the state and federal levels. Generally, these enforcement actions highlighted the importance of appropriate data retention policies, security safeguards, and timely and accurate data breach notifications. Finally, the FTC also remained active in adjacent issue areas like cybersecurity, with claims against companies for misrepresentations and inadequacies regarding their data security practices.

Third, build in observability and human oversight from day one – log what the agent accesses and flag when it encounters sensitive data, so stops can be put in place when people are impacted.” Vague, catch-all privacy statements flag a red card with the ICO where agents https://themors.com/europe-bets-on-control-shaping-digital-sovereignty-in-an-ai-world/ make decisions that directly affect people. These systems are increasingly embedded in real workflows, shaping what users see and how businesses operate. “The biggest challenge is that startups are being asked to define and govern systems whose value often comes from being flexible and adaptive. “The ICO’s guidance is a necessary step forward, but it exposes a gap between how startups build and how regulators expect systems to behave. For any startup building products that use AI agents, systems that act autonomously on users’ behalf across multiple platforms and services, this is the most important regulatory development of 2026 so far.

  • Cybersecurity and data privacy issues posed challenges and opportunities for growth for businesses in 2025.
  • Its draft guidance on agentic AI sets out what UK startups deploying these systems need to demonstrate, and most aren’t ready for it.
  • “So far, AI-related litigation has been based on existing regimes, whether framed as data misuse, consumer protection, copyright infringement or disputes as to liability. In parallel, data, competition and financial regulators are starting to pursue enforcement action. While this will continue – including with the further testing of collective redress mechanisms – we can expect to see cases brought under new AI-specific legislation joining the swell of AI disputes and regulatory enforcement in the years ahead.”
  • As of January 2025, 144 countries had enacted national data privacy laws, placing 82% of the world’s population—approximately 6.64 billion people—under some form of statutory data protection, according to the IAPP’s Global Privacy Law and DPA Directory.

We outline key developments, including draft Codes of Practice, new governance structures, voluntary compliance initiatives and practical tools to support organisations preparing for compliance across the EU. The EU AI Act is moving into its implementation phase, so transparency obligations and enforcement milestones are approaching. We explain what has changed, what it means for organisations, and the practical steps to consider now. The ICO is planning to update and amend its guidance over the coming months; it will be important to follow this to gauge the real practical impact of some of the provisions.

  • As a result, legislative activity in the realm of consumer data privacy may continue at the U.S. state level, an apparent trend under the Biden administration.
  • The HIPAA Security Rule requires that covered entities implement appropriate physical and technical safeguards to ensure the confidentiality, integrity and security of the ePHI.
  • “New data protection laws are coming online, and existing privacy regimes are being reformed, across a number of important markets – including Indonesia, India, Vietnam and Australia. These laws can have accelerated timelines for implementation and significant divergences from GDPR. Finding common ground and outlier requirements, as well as tracking guidelines as they emerge, will be key parts of successful data strategies for organisations operating in APAC.”
  • Why agent-compatible digital public infrastructure is the next investment governments cannot defer
  • If the standard becomes too theoretical it risks favouring large incumbents over startups who are often the ones driving real innovation.”

With federal consensus unlikely in the near term, US organizations should expect more fragmentation in 2026, especially as states continue to enact laws aimed at regulating AI. Below, we break down key trends and what they mean for organizations navigating an increasingly complex global environment. The Information Commissioner’s Office has taken a different approach to working with the public sector over the past three years, almost entirely avoiding fines, but increasing the use of public reprimands – which typically issue demands for improved practices. The aim of that missive was “insisting that the government must go further and faster to ensure Whitehall, and the wider public sector put their practices in order”, according to a newly published update from the commissioner. Such enterprises, referred to as SDF, can be classified by the government based on the volume and sensitivity of personal data being processed, the risks to user rights, and the potential impact on the country’s sovereignty and integrity, among other factors.

data protection news

EDPB meets with EU Commissioner McGrath and adopts common data breach notification template

The risk is for early-stage startups moving quickly with lean teams where the compliance burden can slow experimentation and increase cost. The startups that adapt fastest won’t be those that avoid regulation, but those that design for it from day one.” Poor data quality or unclear governance will become compliance risks very quickly. Startups will need to move beyond treating AI as a feature and instead design systems with traceability, auditability and clear decision boundaries from the outset. This means mapping data flows, clearly defining roles and responsibilities in multi-agent environments, and stress-testing how their products handle consent, user rights, and unexpected outcomes.

data protection news

  • Organisations will also need to continue to monitor AI-related privacy litigation, which is playing a crucial role in clarifying how privacy laws apply to various forms of AI and machine learning.
  • The flowdown requirements in CMMC are a clear example of how organizations are being tasked with greater accountability for their supply chains.
  • The ICO says the Data Use and Access Act 2025 makes changes to data protection law that may affect organisations using personal information and has published a preparation checklist to help them get ready.
  • Irish Data Protection Commission, Irish Data Protection Commission fines TikTok €530 million and orders corrective measures following Inquiry into transfers of EEA User Data to China (May 2, 2025), available here.
  • However, more than half of high-risk cases reported in the first three months of the year failed to inform people who were affected, the ODPA said.

In supervisory practice, the initiative is considered a historic opportunity. This specific consulting expertise is to be preserved, while specialized expertise in complex, overarching issues will be more targeted in the future. At the same time, the state data protection officers emphasize that federalism should not be abolished but intelligently interlinked. This prevents multiple reviews of identical issues by different state offices. For modern supervision, standardized examination procedures and a targeted bundling of competencies for overarching issues are needed.

It said the company asks users to sign up for its paid premium membership if they want to see all the users who have visited their profile pages. VIENNA – A data protection group on May 5 filed a complaint in Austria against professional networking platform LinkedIn, accusing it of charging users to see who has viewed their profiles. On the contrary, instead of generating real economic value, “dark data” generates high storage costs and create significant security risks. These data graveyards lead to neither better decisions nor improved customer outcomes. Yet organisations often collect far more data than can be meaningfully evaluated.

As the US continues to accumulate a patchwork of state-specific data protection laws, businesses operating across states or deploying and employing AI face enormous operational complexity. At the same time, the benefits of data protection rules and compliance are also well documented. As of January 2025, 144 countries had enacted national data privacy laws, placing 82% of the world’s population—approximately 6.64 billion people—under some form of statutory data protection, according to the IAPP’s Global Privacy Law and DPA Directory. Why agent-compatible digital public infrastructure is the next investment governments cannot defer Read the most recent articles written by Sam Trendall – Six months on, how is the digital roadmap progressing?

By cong

Leave a Reply

Your email address will not be published. Required fields are marked *