"Right to be forgotten" dispute between Canadian Privacy Commissioner and Google escalates to court.
Following investigations initiated under the Personal Information Protection and Electronic Documents Act ("PIPEDA"), the Office of the Privacy Commissioner of Canada ("OPC") recommended that Google remove certain personal content from its search results. Upon Google's refusal to implement these recommendations, the OPC brought the matter before the Federal Court of Canada to make the decisions legally binding. While the judicial process opens up debate over a private company's responsibility to balance public interest and privacy in search results, it will also determine how the "reasonable purpose" principle in PIPEDA will be interpreted by the court.
Click on the link for the full story.
Landmark settlement between Meta and US states sets new compliance standards in digital safety.
The historic settlement reached between Meta and state attorneys general voluntarily implements radical security measures that courts found unconstitutional to enact via legislation. The agreement includes strict age verification accuracy rates for users under 18, a two-hour daily usage limit, nighttime access restrictions, bans on cosmetic filters, and non-algorithmic chronological feed options. Experts emphasize that these terms—which enhance parental control and prevent repeated exposure to sensitive content—could turn into a global compliance standard across the industry.
Click on the link for the full story.
European Commission prepares dedicated AI strategy for the cultural and creative sector.
The European Commission launched a public consultation process for a new strategy planned for publication in 2027 to support the fair and ethical use of AI in cultural and creative industries. The study addresses critical issues such as copyright licensing, unauthorized use of artists' voices and images, content dissemination, and preservation of cultural diversity. Aiming for a human-centric approach and European digital sovereignty, the strategy rests on three pillars: innovation, fair business models, and capacity building for the sector.
Click on the link for the full story.
The role of Chief Information Security Officers becomes critical for data protection in enterprise AI projects.
With the widespread adoption of AI in organizations, implementing traditional privacy principles such as data minimization and purpose limitation is becoming increasingly dependent on technical security controls. Noting that the way AI systems process, combine, and log data creates new risk surfaces, experts emphasize that Chief Information Security Officers (CISOs) must not only remain responsible for system protection, but also translate privacy policies into enforceable technical controls. Organizations are recommended to establish an AI inventory and update incident response plans.
Click on the link for the full story.
Concurrent application of GDPR and AI Act in the EU triggers compliance crisis for healthcare AI platforms.
The joint entry into force of the GDPR and the AI Act in the European Union creates severe legal and technical contradictions for dynamically operating medical AI applications. Highlighting that transparency and access rights cannot be fully implemented due to algorithmic complexity, and that correcting inaccurate data does not immediately erase biases embedded in model training, experts advise healthcare platforms to develop layered and modular consent mechanisms suited to dynamic data structures, conduct end-to-end data cleansing processes, and maintain human oversight channels.
Click on the link for the full story.
AI-powered wearable technologies increase passive data collection risks and privacy vulnerabilities for children.
AI-enabled glasses and smart devices becoming prevalent in schools lead to the recording of children's facial, voice, and biometric data simply due to their presence in the environment, even if they are not users themselves. Noting that traditional legislation like the US Children's Online Privacy Protection Act focuses directly on individuals using the service, experts urge lawmakers, schools, and tech companies to implement comprehensive regulations that protect children not merely as "users" of technology, but also as passive "subjects".
Click on the link for the full story.
Australia introduces "fair and reasonable" era in personal data protection with new draft bill.
The Australian Attorney-General's Department opened a new reform package for public consultation under the Privacy Amendment (Personal Data Protection) Bill 2026, introducing a "fair and reasonable" test for processing personal data. Deeming companies' reliance solely on explicit consent insufficient, the regulation introduces the right to erasure (right to be forgotten), strict supervision for next-generation technologies like smart glasses, and digital identity protection mechanisms. Experts emphasize that integrating privacy into product design and governance processes has become critical for organizations.
Click on the link for the full story.
Cyberattacks on US critical infrastructure reveal the rise of AI-enhanced nation-state threats.
The US Cybersecurity and Infrastructure Security Agency issued an advisory regarding nation-state cyberattacks targeting water and wastewater systems, urging critical infrastructure entities to secure internet-exposed systems. Experts emphasize that threat actors empowered by AI can quietly establish footholds within systems, making attack risks systematic alongside growing geopolitical tensions. Organizations are advised to increase security and monitoring controls, re-balance costs against risks, and align legal, compliance, and information security teams.
Click on the link for the full story.
Danish Data Protection Authority grants conditional approval for automated facial recognition at football matches.
The Danish Data Protection Authority authorized football club Lyngby Boldklub to process biometric data using automated facial recognition technology at the stadium under the public interest grounds. Subject to the conditions that the club remains in the Danish Super League and that data belonging to individuals not on the stadium suspension list is deleted immediately, only data of banned individuals will be retained after each match. The Authority also permitted CCTV footage to be retained for longer than 30 days for resolving specific disputes.
Click on the link for the full story.
Spanish Data Protection Authority imposes administrative fine on company for continuous workplace audio recording.
The Spanish Data Protection Authority imposed an administrative fine of €4,000 on a company that installed cameras recording both audio and video in workplace areas for security and staff monitoring purposes. Considering continuous audio recording an excessive intrusion into employees' private lives, the Authority emphasized that less intrusive methods could have been used for burglary prevention or disciplinary proceedings. Ruling that the practice violated the GDPR data minimization principle, the DPA ordered the company to disable the audio recording feature on the cameras.
Click on the link for the full story.