Detailing Zimbabwe's online security, AI efforts.
The Media Institute of Southern Africa issued a report highlighting key elements of Zimbabwe's digital sector including its National AI Strategy, Cyber and Data Protection Act and the enforcement efforts of the National Digital Regulatory Committee. As innovation advances, MISA urged the government to accelerate digital security standards by proposing a review of the Postal and Telecommunications Amendment Bill, the Broadcasting Services Act and the Cyber and Data Protection Act to meet current data protection concerns. The group said legislation alone is not enough and that "a rights-based approach requires independent oversight, meaningful public participation, and algorithmic transparency."
Click on the link for the full story.
EDPB, AMLA to release joint guidance on protecting sensitive financial data.
The European Data Protection Board and Anti-Money Laundering Authority announced they will develop joint guidance to help organizations better protect personal data and navigate financial cybercrime threats. The EDPB said the guidelines "will set out in practical terms how partnerships can be built so that effective information sharing and the protection of personal data go hand in hand. This will give everyone involved, from companies and supervisors to (Financial Intelligence Units) and data protection authorities, more clarity on how to set up successful partnerships."
Click on the link for the full story.
Saskatchewan's OIPC urges government to focus on privacy protections for underage users.
The Office of the Saskatchewan Information and Privacy Commissioner released a report detailing its key goals and urged the government to prioritize children's online safety measures for social platforms instead of implementing an overall ban, CTV News reports. Privacy Commissioner Grace Hession David said social media bans for underage users may not effectively prevent online harms and could "serve as nothing other than a false sense of security to parents when the real focus should be with the social media sites that offer dangerous options to young people."
Click on the link for the full story.
Australia's Senate orders OAIC to provide information on credit card company's data breach.
Australia's Senate ordered the Office of the Australian Information Commissioner to provide information related to American Express' alleged cybersecurity vulnerabilities that led an employee to breach a consumer's information, ABC reports. The OAIC previously released a report detailing the incident and threatened to take legal action against the consumer who filed the complaint if they shared the full report describing the company's alleged security inadequacies. Sen. David Shoebridge said, "it should not have to take an order from the Senate to force the release" of "an important privacy report."
Click on the link for the full story.
Ireland's DPC issues 2025 annual report.
Ireland's Data Protection Commission released its annual report for 2025 detailing its enforcement efforts, including 11,734 resolved data protection cases and four large scale investigations. The DPC also noted its "sharenting survey," which aims to gather information about how parents share their children's image and personal information online. Although 3 out of 4 parents have shared online content about their children within the last year, the survey found 66% of parents said sharing children's images could have risks, with 55% raising concerns about AI models potentially processing those images.
Click on the link for the full story.
Alberta officials face class-action lawsuit over voting data.
Alberta's government and elections office are facing a class-action lawsuit after the personal information of more than 2.9 million voters was breached, CBC News reports. If the courts certify the lawsuit, individuals could seek damages. Heather Jenkins, press secretary to Justice Minister Mickey Amery, said in a statement, "the protection of Albertans' personal information is taken very seriously by our government."
Click on the link for the full story.
US House passes the KIDS Act.
The U.S. House of Representatives passed the Kids Internet and Digital Safety Act 29 June, progressing efforts to pass a comprehensive federal online safety bill for underage users. Writer Lexie White unpacks the bill's key provisions and bipartisan pushback from advocacy groups and lawmakers over age verification requirements and the potential privacy implications.
Click on the link for the full story.
China proposes updated privacy standard with new AI, sensitive data obligations.
China's National Technical Committee 260 on Cybersecurity published a draft framework proposing new compliance requirements for AI developers and stricter requirements for sensitive personal data, MLex reports. The draft framework also provides guidance for companies navigating conflicting cross-border data laws and would amend the national personal information standard to better align with the Personal Information Protection Law. The proposed changes would be voluntary but would serve as a "de-facto" standard for companies operating in China. The draft is available for public comment until 16 Aug.
Click on the link for the full story.
Bermuda's DPA releases first annual report.
The Office of the Privacy Commissioner of Bermuda published its inaugural annual report covering the period from 1 April 2025 to 31 March 2026, Bernews reports. The report contains data on the total number of filings with PrivCom during this period, including individual complaints and data breach reports from organizations. "Apart from publishing data on community engagement with the rights regime, the Annual Report serves as an important record for Bermuda in two respects: The report chronicles the public authority's transition from pre-implementation preparedness activities to more substantive regulatory enforcement," a PrivCom spokesperson said.
Click on the link for the full story.
Belgium, Spain DPAs issue joint video game guidance to comply with data protection laws.
Spain's data protection authority, the Agencia Española de Protección de Datos, and Belgium's Data Protection Authority issued joint guidance containing recommendations and best practices for video game developers to comply with data protection laws. The guidance features insight into how personal data is processed within video games and by stakeholders in the video game industry. The AEPD and ADP's recommendations and best practices are geared toward each phase of a game's life cycle, from development and pre-production, to release and post-production.
Click on the link for the full story.