The California Privacy Protection Agency introduced a new audit proposal requiring data brokers to prove deletion requests.
The California Privacy Protection Agency prepared an audit proposal requiring data brokers to verify personal data deletion requests not merely by declaration, but through concrete evidence such as system testing, data maps, and log records. By imposing the requirement to prove that derived profiles and copies held by third-party service providers have been deleted alongside the primary data, this approach marks a significant shift in data protection from abstract commitments to technically auditable and verifiable compliance processes.
Click on the link for the full story.
India strengthens its digital governance infrastructure by preparing a new AI-specific law.
The Government of India initiated stakeholder consultations to draft a standalone law specifically for artificial intelligence, moving beyond existing information technology legislation. While projects and security infrastructures expanding the country's AI ecosystem are being supported, children's online safety, intermediary liability of social media platforms, and deepfake risks are being intensively debated in parliament. Furthermore, judicial decisions and rising cybersecurity costs highlight the urgency of balancing data-driven innovation with legal oversight.
Click on the link for the full story.
The use of smart glasses causing privacy and workplace violations fuels growing legal and social debates in Europe.
The use of smart glasses in workplaces and public spaces for covert recording has prompted data protection authorities across Europe to take action. While countries like France and Norway have published guidelines focused on individual awareness and social sensitivity, Germany is debating a total ban option based on its legal history regarding hidden recording devices. Shaped under trade secret protection, privacy rights, and the EU Data Act, this process highlights the inadequacy of legal preservation mechanisms and the need for new regulations against technological innovations.
Click on the link for the full story.
The independence and positioning of the Data Protection Officer gain importance under the Chilean Data Protection Law.
While Chile's new Personal Data Protection Law highlights the role of the Data Protection Officer ("DPO") in organizations, the internal positioning and independence of this role spark debate. While regulations require the DPO to report directly to the highest governing body, the advantages and conflict-of-interest risks of structuring the role under cybersecurity, IT, legal, or compliance departments are being evaluated. Experts emphasize that the DPO must not fall into a position of auditing their own decisions and must execute their duties independently, free from conflicts of interest.
Click on the link for the full story.
The rapid increase in generative AI usage requires the restructuring of corporate governance and risk processes.
Widespread and unauthorized use of third-party generative AI tools by employees poses serious corporate risks in areas such as information confidentiality, data accuracy, and copyright. Rather than consolidating all AI systems under a single, cumbersome governance framework or banning the technology outright, introducing phased and use-centric control mechanisms focused on input restrictions, human oversight, and AI literacy is recommended.
Click on the link for the full story.
South Korea adopts new legislative amendment subjecting the use of personal data for AI training to regulatory approval.
The National Assembly of South Korea is on the verge of approving a critical amendment to the Personal Information Protection Act to support AI development. The regulation permits the use of personal data for AI training without the data subject's explicit consent and beyond the original collection purpose, conditional upon case-by-case approval by the Personal Information Protection Commission. Shifting decision-making authority entirely to the regulatory board rather than companies, this model brings along bureaucratic hurdles and corporate oversight debates in data protection.
Click on the link for the full story.
Fenty Beauty's AI-powered chatbot brings new privacy risks while offering personalized beauty recommendations.
Fenty Beauty's AI-powered beauty advisor Rose Amber, offered via WhatsApp, raises concerns regarding sensitive personal data collection while driving conversational commerce. Indirect data regarding ethnic origin and health conditions are collected through questions about skin tone, hair texture, and skin concerns. Highlighting that the informal chat format increases consumer vulnerability, it is emphasized that brands must comply with AI output transparency, bias risk, child safety, and data privacy standards.
Click on the link for the full story.
The California Privacy Protection Agency announced DROP platform audits and a new fee increase for data brokers.
The California Privacy Protection Agency announced that 450,000 requests were processed in the first week via the DROP platform, which allows consumers to delete their data. Opening draft rules for public comment regarding three-year independent audits starting in 2028 to oversee data brokers' compliance processes, the board raised the 2027 data broker registration fee to USD 9,500 to cover infrastructure, verification, and staffing costs. Additionally, the newly established Audits Division shared its risk-based, active review approach with the public.
Click on the link for the full story.
The Italian DPA fined Piaggio €460,000 for unlawfully monitoring and retaining employee emails.
The Italian Data Protection Authority imposed an administrative fine of €460,000 on Piaggio for unlawfully conducting workplace monitoring by systematically retaining employee emails and log records for years and failing to respond to account deactivation requests. The decision emphasized that an employer cannot conduct extensive retrospective email reviews even under the defense rights justification, that email privacy and data minimization principles were violated, and that employees retain a reasonable expectation of privacy in the workplace.
Click on the link for the full story.
The Hungarian DPA fined an online store for lacking a privacy notice on its website.
The Hungarian Data Protection Authority imposed an administrative fine of HUF 10,000,000 (approx. €27,300) on an online store operator due to the absence of a privacy notice on its website and un-transparent data processing practices. The decision stated that incomplete or missing information regarding processing purposes, legal bases, retention periods, and recipient categories across order, registration, and newsletter processes violated the transparency and accountability principles of the GDPR.
Click on the link for the full story.