Garante fines airline over alleged health data processing, deletion lapses.
Italy's data protection authority, the Garante, issued a 180,000 euro fine to Emirates after the airline allegedly did not comply with data deletion and transparency regulations when collecting passengers' health information, Reuters reports. The Garante found that while the processing of passengers' health information was itself lawful, the company retained health data for seven years, "which it considered excessive and disproportionate." The Garante also noted the company must provide clear privacy information, whether on its website or directly through assisting passengers.
Click on the link for the full story.
American Express Australia found to violate citizen's privacy after employee illegally accessed customer PI.
Australian Privacy Commissioner Carly Kind issued a report determining American Express' Australian subsidiary was found to have infringed on a citizen's privacy by failing to prevent unauthorized access of their personal information. The report examined the risk of employees using their internal permissions to improperly access personal information collected by the company more broadly throughout the economy. Following the investigation, American Express will be forced to pay the complainant a specified sum for damages, issue an apology and implement access controls.
Click on the link for the full story.
ICO issues statement on UK's proposed under-16 social media ban.
Following the government's introduction of legislation proposing to ban children under age 16 from accessing social media, the U.K. Information Commissioner's Office reminded platforms that existing data protection law still applies to processing minors' personal data. "We will continue to engage with government, as well as other regulators, to ensure that any legislative changes deliver robust protection for children online,” the ICO statement reads. “Whilst government develop its plans, the existing law still applies, and organisations should be clear that their data protection obligations remain.” Editor's note: IAPP Staff Writer Lexie White unpacked the U.K.'s proposed ban in a recent article.
Click on the link for the full story.
Hackers are using residential networks to conduct cyberattacks.
Nation-state hackers are using backdoor software to easily hide cyberattacks, raising concerns about the security of consumers' home devices, The Wall Street Journal reports. Preinstalled software from malicious apps and mobile games has allowed nation-state cyberattackers to conduct extensive cyberattacks through users' devices without having to hack the devices themselves. Assistant Director of the U.S. Federal Bureau of Investigation's Cyber Division Brett Leatherman warned if the “actors can get U.S.-based IP space, they have a leg up in being able to target government agencies, industry, and others.”
Click on the link for the full story.
France's ANSSI will not certify products without quantum-resistant encryption.
In an effort to urge organizations to update their systems, France's National Agency for the Security of Information Systems announced it will no longer certify products that do not have quantum-resistant encryption by 2027, Reuters reports. ANSSI Chief of Staff Samih Souissi said organizations' lack of quantum-safe systems is “not only a technical issue. It's a matter of governance, industrial planning, regulation, and sovereignty.”
Click on the link for the full story.
IAB expands its Diligence Platform to EU with upcoming launch in Germany.
On 1 July, the Interactive Advertising Bureau will launch its expanded Diligence Platform in Germany. The centralized tool that will enable EU adtech stakeholders to manage and share diligence assessments was first made available in the U.S. in 2024. The IAB Diligence Platform, powered by compliance vendor SafeGuard Privacy, is launching in partnership with Bundesverband Digitale Wirtschaft, one of the IAB's largest members in the EU. German adtech companies will also have a certification program available to them through Nexidia. The Diligence Platform contains three new embedded AI features to help privacy teams make operational decisions.
Click on the link for the full story.
US request for Ugandan citizens' health data raises concerns.
The U.S. request within a new agreement to access the sensitive health information of citizens in Uganda to determine if the U.S. should provide health aid has raised concerns about how citizens' sensitive information could be transferred and collected, ProPublica reports. Uganda has agreed to share health data, though attorney and digital rights expert Frank Ssekamwa highlighted the privacy implications, noting, "If I'm someone who has had health issues, can you deny me a visa because of the health issues I'm having?"
Click on the link for the full story.
Apple's email privacy feature changes could allow companies to block anonymous email addresses.
Apple said it will change its Hide My Email feature, moving anonymously-generated email addresses to @private.icloud.com, TechCrunch reports. The change could make it easier for companies to block consumers from signing up for services using anonymous emails. Users that have already used the feature for certain online platforms won't be affected by the change.
Click on the link for the full story.
Canada's Bill C-36 introduces privacy reforms, enforcement changes.
Canada introduced Bill C-36, the Protecting Privacy and Consumer Data Act aiming to amend the Personal Information Protection and Electronic Documents Act and restructure the Office of the Privacy Commissioner's enforcement role to establish the Digital Safety and Data Protection Commission.
Click on the link for the full story.
European Parliament approves Digital Omnibus amendment, postponing certain AI Act deadlines.
The European Parliament voted to approve an amendment in the Digital Omnibus package that would postpone certain application dates of the AI Act. The measure also contains a ban on apps that can be used to create nonconsensual deepfake imagery and removes overlapping requirements for AI embedded in machine products, which will still need to meet sectoral safety requirements. The postponed deadlines are 2 Dec. 2027 for standalone high-risk systems and 2 Aug. 2028 for AI systems embedded as safety components in products. Rules for watermarking and labeling synthetic content were delayed until 2 Dec. of this year.
Click on the link for the full story.