The EDPB took action to examine the impacts of the US Supreme Court ruling on the EU-US Data Privacy Framework.
Following the US Supreme Court ruling increasing presidential authority over independent agencies, the European Data Protection Board (EDPB) sent an official letter to the European Commission regarding the future of the EU-US Data Privacy Framework. Pointing out that compromising the independence of the Federal Trade Commission could negatively affect the level of data protection, the EDPB requested a detailed assessment. As industry representatives and experts debate the legal implications of the decision, it is noted that the EU will closely monitor the situation.
Click on the link for the full story.
New transparency obligations under the AI Act shape product design and governance processes.
Transparency rules under Article 50 of the European Union Artificial Intelligence Act entered into force, making machine-readable marking, content labeling, and interaction disclosures mandatory. While turning transparency from an abstract principle into a technical and organizational responsibility, this regulation also impacts global entities offering outputs outside the EU. Similarly, ongoing public consultations and province-level guidelines in Canada emphasize that transparency in AI must be integrated into systems from the outset.
Click on the link for the full story.
The US Senate Commerce Committee passed bills aimed at enhancing children's online safety and AI privacy.
The US Senate Commerce Committee approved the Kids Online Safety Act along with several AI-focused children's privacy bills and referred them to the Senate floor. Introducing a duty of care for tech companies and aiming to limit addictive designs, the regulations intend to increase parental control, restrict the processing duration of children's data by AI chatbots, and investigate the impacts of AI-enabled toys. The bills spark debates balancing children's protection with data privacy concerns.
Click on the link for the full story.
The US Senate examined the risks of surveillance-driven dynamic pricing on consumer rights and data privacy.
The US Senate Judiciary Committee discussed the risks posed by "surveillance pricing," which refers to offering personalized, different prices using AI and behavioral data. Collecting consumer data via opaque algorithms to determine prices based on "willingness to pay" was characterized as a severe violation of privacy and exploitation. Highlighting state-level banning initiatives, it was emphasized that an overarching federal regulation is urgently needed at the national level to protect consumers from such data exploitation.
Click on the link for the full story.
Serbia opened the draft of its new Law on Personal Data Protection for public consultation.
The Ministry of Justice of Serbia published the draft of a new Law on Personal Data Protection to modernize the existing legislation. While separating data processing by law enforcement from the general regime, the draft introduces detailed rules specifically targeting AI and video surveillance for the first time. A modular data transfer model aligned with EU Standard Contractual Clauses has been adopted, alongside a ban on mass biometric identification. Setting data protection impact assessment requirements for high-risk AI systems, the regulation foresees reasonable increases in administrative fines.
Click on the link for the full story.
China introduces innovative regulations and relaxed compliance measures in AI and data governance.
Seeking to lead global AI governance by establishing the World AI Cooperation Organization in Shanghai, China published new rules covering anthropomorphic AI interactions, financial AI, and combating cyber violence. Additionally, the Cyberspace Administration of China issued guidelines resolving uncertainties in cross-border data transfer processes. Starting 1 September, simplified compliance measures facilitating notification, consent, and audit processes for small-scale companies processing data of fewer than 100,000 individuals will enter into force.
Click on the link for the full story.
The NAI published guidance on the responsible use of AI and agentic workflows in advertising.
The Network Advertising Initiative (NAI) published voluntary principles to guide the use of AI and agentic workflows in the advertising technology sector. The guidance contains dos and don'ts for member companies to inventory, test, ensure transparency, and monitor risks in AI systems. In the absence of binding regulations, the guidance focuses on emerging privacy risks in advertising, aiming to help companies achieve responsible and controlled technology integration.
Click on the link for the full story.
The California Privacy Protection Agency's new Audits Division deploys flexible, data-driven audit models.
The California Privacy Protection Agency is launching routine checks and sectoral reviews in data privacy through its newly established Audits Division. Initiating its first comprehensive audit on the gig economy, the unit adopts an approach focused on information gathering, technical testing, and identifying compliance trends rather than mere penalization. Focusing on automated decision-making, cybersecurity audits, and employee privacy, the division aims to strengthen data-driven governance.
Click on the link for the full story.
The EU Digital Omnibus Regulation brings flexibilities and new compliance processes to the AI Act.
The European Union enacted the Digital Omnibus regulation introducing amendments to the AI Act, postponing compliance deadlines for high-risk AI systems and watermarking obligations. While banning AI systems that generate nonconsensual intimate material and child abuse content, the regulation provided flexibility for processing sensitive personal data to detect bias. Additionally, administrative burdens on small and medium-sized enterprises were lightened, and the oversight powers of the AI Office were expanded.
Click on the link for the full story.
Browser-based automated consent regulation under the EU Digital Omnibus offers a solution to the cookie banner problem.
The new Article 88b regulation under the European Union's Digital Omnibus proposal allows users to automatically transmit their privacy preferences via browser settings instead of cookie banners. Removed from the Council of the EU's position paper due to pressure from publishing lobbyists, the provision aims to reduce consent fatigue and dark patterns through standards used in the US, such as Global Privacy Control. Experts argue that preserving the regulation during upcoming trilogue negotiations will bring a permanent and effective solution to the cookie banner issue.
Click on the link for the full story.